Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-41228

Опубликовано: 20 мая 2025
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to steal cookies or redirect to malicious websites.

EPSS

Процентиль: 57%
0.00891
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.3
github
больше 1 года назад

VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to steal cookies or redirect to malicious websites.

CVSS3: 4.3
fstec
больше 1 года назад

Уязвимость программных продуктов VMware ESXi, VMware vCenter Server, Cloud Foundation, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю осуществлять межсайтовые сценарные атаки (XSS)

EPSS

Процентиль: 57%
0.00891
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-79