CVE-2025-23392: Reflected XSS in SystemsController.java in spacewalk-java
A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in spacewalk-java allows execution of arbitrary Javascript code on target systems.This issue affects Container suse/manager/5.0/x8664/server:5.0.4.7.19.1: from ? before 5.0.24-150600.3.25.1; Container suse/manager/5.0/x8664/server:5.0.4.7.19.1: from ? before 5.0.24-150600.3.25.1; Container suse/manager/5.0/x8664/server:5.0.4.7.19.1: from ? before 5.0.24-150600.3.25.1; Container suse/manager/5.0/x8664/server:5.0.4.7.19.1: from ? before 5.0.24-150600.3.25.1; SUSE Manager Server Module 4.3: from ? before 4.3.85-150400.3.105.3; SUSE Manager Server Module 4.3: from ? before 4.3.85-150400.3.105.3; SUSE Manager Server Module 4.3: from ? before 4.3.85-150400.3.105.3; SUSE Manager Server Module 4.3: from ? before 4.3.85-150400.3.105.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23392?
CVE-2025-23392 is considered a high-severity vulnerability due to its potential for allowing arbitrary JavaScript execution.
How do I fix CVE-2025-23392?
To fix CVE-2025-23392, upgrade SUSE Manager Server to version 5.0.24-150600.3.25.1 or later.
What software is affected by CVE-2025-23392?
CVE-2025-23392 affects SUSE Manager Server versions prior to 5.0.24-150600.3.25.1 and SUSE Manager Server Module versions prior to 4.3.85-150400.3.105.3.
What type of vulnerability is CVE-2025-23392?
CVE-2025-23392 is classified as an Improper Neutralization of Script-Related HTML Tags, also known as Basic Cross-Site Scripting (XSS).
What are the consequences of exploiting CVE-2025-23392?
Exploiting CVE-2025-23392 can lead to the execution of arbitrary JavaScript code on affected systems, potentially compromising security.