PT-2025-36793 · Proxmox · Proxmox Virtual Environment 8.4

Khankishiyev-J

·

Published

2025-09-09

·

Updated

2025-09-10

·

CVE-2025-57539

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Proxmox Virtual Environment versions 8.4
Description: A stored cross-site scripting (XSS) vulnerability exists in the U2F Origin field of the Datacenter configuration. Authenticated users can store malicious input which is rendered unsafely in the Web UI and executed when viewed by other users. This could potentially lead to session hijacking or other attacks.
Recommendations: Update to a newer version that contains a fix for this issue. As a temporary workaround, sanitize user input for the U2F Origin field in the Datacenter configuration.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-57539

Affected Products

Proxmox Virtual Environment 8.4