PT-2025-48241 · Unknown · Apache Skywalking
Published
2025-11-27
·
Updated
2026-04-13
·
CVE-2025-54057
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache SkyWalking versions prior to 10.3.0
Description
The software contains an Improper Neutralization of Script-Related HTML Tags in a Web Page issue, also known as a Basic Cross-Site Scripting (XSS) flaw. This allows attackers to inject malicious JavaScript into SkyWalking UI fields, potentially leading to persistent XSS, session hijacking, and unauthorized actions when administrators view compromised pages. The flaw is due to improper sanitization in multiple input fields within the SkyWalking UI. Approximately 2,600 potentially affected devices have been identified.
Recommendations
Upgrade to version 10.3.0 to resolve the issue.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Skywalking