CVE-2025-23393: Reflected XSS in spacewalk-java
A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in spacewalk-java allows execution of arbitrary Javascript code on users machines.This issue affects Container suse/manager/5.0/x8664/server:5.0.4.7.19.1: from ? before 5.0.24-150600.3.25.1; SUSE Manager Server Module 4.3: from ? before 4.3.85-150400.3.105.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23393?
CVE-2025-23393 is classified as a critical severity vulnerability due to its potential to allow arbitrary JavaScript code execution.
How do I fix CVE-2025-23393?
To fix CVE-2025-23393, upgrade your SUSE Manager to version 5.0.24-150600.3.25 or later.
What systems are affected by CVE-2025-23393?
CVE-2025-23393 affects SUSE Manager Server version 5.0.4.7.19.1 and earlier, as well as SUSE Manager Server Module version 4.3.85-150400.3.105.3 and earlier.
What type of vulnerability is CVE-2025-23393?
CVE-2025-23393 is an Improper Neutralization of Script-Related HTML Tags in a Web Page vulnerability, commonly known as a basic Cross-Site Scripting (XSS) flaw.
What are the risks of CVE-2025-23393 if left unpatched?
If left unpatched, CVE-2025-23393 could be exploited to execute malicious JavaScript on users' machines, potentially leading to data theft or other malicious actions.