PT-2025-48241 · Unknown · Apache Skywalking

Published

2025-11-27

·

Updated

2026-04-13

·

CVE-2025-54057

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache SkyWalking versions prior to 10.3.0
Description The software contains an Improper Neutralization of Script-Related HTML Tags in a Web Page issue, also known as a Basic Cross-Site Scripting (XSS) flaw. This allows attackers to inject malicious JavaScript into SkyWalking UI fields, potentially leading to persistent XSS, session hijacking, and unauthorized actions when administrators view compromised pages. The flaw is due to improper sanitization in multiple input fields within the SkyWalking UI. Approximately 2,600 potentially affected devices have been identified.
Recommendations Upgrade to version 10.3.0 to resolve the issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-54057
GHSA-V6X2-4Q87-RF82

Affected Products

Apache Skywalking