PT-2025-44398 · Suse · Suse Manager Server Lts 4.3+1

Published

2025-10-28

·

Updated

2025-10-30

·

CVE-2025-53883

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Container suse/manager versions prior to 5.0.28-150600.3.36.8 SUSE Manager Server LTS 4.3 versions prior to 4.3.88-150400.3.113.5
Description An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) issue exists, allowing attackers to execute arbitrary JavaScript through a reflected Cross-Site Scripting (XSS) flaw in the search fields. The issue enables privileged attackers to execute arbitrary JavaScript.
Recommendations Update Container suse/manager to version 5.0.28-150600.3.36.8 or later. Update SUSE Manager Server LTS 4.3 to version 4.3.88-150400.3.113.5 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-53883
SUSE-SU-2025:3826-1
SUSE-SU-2025:3827-1

Affected Products

Suse Manager Server Lts 4.3
Suse Manager