PT-2025-36793 · Proxmox · Proxmox Virtual Environment 8.4
Khankishiyev-J
·
Published
2025-09-09
·
Updated
2025-09-10
·
CVE-2025-57539
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Proxmox Virtual Environment versions 8.4
Description:
A stored cross-site scripting (XSS) vulnerability exists in the U2F Origin field of the Datacenter configuration. Authenticated users can store malicious input which is rendered unsafely in the Web UI and executed when viewed by other users. This could potentially lead to session hijacking or other attacks.
Recommendations:
Update to a newer version that contains a fix for this issue. As a temporary workaround, sanitize user input for the U2F Origin field in the Datacenter configuration.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Proxmox Virtual Environment 8.4