CVE-2025-25018: Kibana Stored Cross-Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25018?
CVE-2025-25018 is classified as a high severity vulnerability due to its potential to allow stored Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2025-25018?
To fix CVE-2025-25018, update your installation of Kibana to the latest version provided by Elastic that addresses this vulnerability.
What is the impact of CVE-2025-25018?
The impact of CVE-2025-25018 includes the potential for attackers to inject malicious scripts that can execute in the context of another user's browser session.
Which versions of Kibana are affected by CVE-2025-25018?
CVE-2025-25018 affects specified versions of Kibana prior to the security update, so it's essential to review the version details provided by Elastic.
How can CVE-2025-25018 be exploited?
CVE-2025-25018 can be exploited by sending specially crafted input during web page generation in Kibana that is not properly sanitized.