CVE-2025-40893: HTML injection in Asset List in Guardian/CMC before 25.5.0
A Stored HTML Injection vulnerability was discovered in the Asset List functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets to inject HTML tags into asset attributes. When a victim views the affected assets in the Asset List (and similar functions), the injected HTML renders in their browser, enabling phishing and possibly open redirect attacks. Full XSS exploitation and direct information disclosure are prevented by the existing input validation and Content Security Policy configuration.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40893?
CVE-2025-40893 is classified as a moderate severity vulnerability due to its potential to allow stored HTML injection.
How do I fix CVE-2025-40893?
To fix CVE-2025-40893, ensure that input validation and sanitization are properly implemented for the Asset List functionality.
Which software versions are affected by CVE-2025-40893?
CVE-2025-40893 affects Guardian/CMC versions up to 25.5.0.
Can an unauthenticated attacker exploit CVE-2025-40893?
Yes, an unauthenticated attacker can exploit CVE-2025-40893 by sending specially crafted network packets.
What impact does CVE-2025-40893 have on users?
CVE-2025-40893 can allow an attacker to execute malicious HTML code when the victim views affected asset attributes.