CVE-2025-37732: Kibana Cross-site Scripting via the Integration Package Upload Functionality
Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to render HTML tags within a user’s browser via the integration package upload functionality. This issue is related to ESA-2025-17 (CVE-2025-25018) bypassing that fix to achieve HTML injection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37732?
CVE-2025-37732 is classified as a moderate severity vulnerability that involves improper input neutralization leading to cross-site scripting.
How do I fix CVE-2025-37732?
To mitigate CVE-2025-37732, it is recommended to update to the latest version of Elastic Kibana that addresses this vulnerability.
Who is affected by CVE-2025-37732?
CVE-2025-37732 affects users of Elastic Kibana where the integration package upload functionality is used.
What exploit does CVE-2025-37732 allow?
CVE-2025-37732 allows an authenticated user to inject and render HTML tags in the browser through cross-site scripting.
Is user authentication required to exploit CVE-2025-37732?
Yes, CVE-2025-37732 requires the attacker to be an authenticated user to exploit the vulnerability.