CVE-2025-22466: XSS
Published Apr 8, 2025
·Updated
Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.
Affected Software
10 affected components
Ivanti Endpoint Manager<2024 SU1, <2022 SU7
Ivanti Endpoint Manager<2022
Ivanti Endpoint Manager=2022
Ivanti Endpoint Manager=2022-su1
Ivanti Endpoint Manager=2022-su2
Ivanti Endpoint Manager=2022-su3
Ivanti Endpoint Manager=2022-su4
Ivanti Endpoint Manager=2022-su5
Ivanti Endpoint Manager=2022-su6
Ivanti Endpoint Manager=2024
Event History
Apr 8, 2025
CVE Published
via MITRE·02:27 PM
Data Sourced
via MITRE·02:27 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-22466?
CVE-2025-22466 has a high severity due to its potential to allow remote unauthenticated attackers to gain admin privileges.
2
How do I fix CVE-2025-22466?
To fix CVE-2025-22466, upgrade to Ivanti Endpoint Manager version 2024 SU1 or version 2022 SU7.
3
What type of vulnerability is CVE-2025-22466?
CVE-2025-22466 is classified as a reflected Cross-Site Scripting (XSS) vulnerability.
4
Is user interaction needed to exploit CVE-2025-22466?
Yes, user interaction is required to exploit CVE-2025-22466.
5
Which versions of Ivanti Endpoint Manager are affected by CVE-2025-22466?
Ivanti Endpoint Manager versions prior to 2024 SU1 and 2022 SU7 are affected by CVE-2025-22466.