CVE-2025-40899: Stored Cross-Site Scripting (XSS) in Assets and Nodes in Guardian/CMC before 26.0.0
A Stored Cross-Site Scripting vulnerability was discovered in the Assets and Nodes functionality due to improper validation of an input parameter. An authenticated user with custom fields privileges can define a malicious custom field containing a JavaScript payload. When the victim views the Assets or Nodes pages, the XSS executes in their browser context, allowing the attacker to perform unauthorized actions as the victim, such as modify application data, disrupt application availability, and access limited sensitive information.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40899?
CVE-2025-40899 has a severity rating that indicates a significant risk due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2025-40899?
To fix CVE-2025-40899, upgrade Guardian/CMC to version 26.0.0 or later, which contains the necessary patches.
Who can exploit CVE-2025-40899?
An authenticated user with privileges to create custom fields can exploit CVE-2025-40899 to execute stored XSS attacks.
What are the potential impacts of CVE-2025-40899?
The potential impacts of CVE-2025-40899 include execution of malicious scripts in the context of other users, leading to data theft or unauthorized actions.
What software versions are affected by CVE-2025-40899?
CVE-2025-40899 affects Guardian/CMC versions prior to 26.0.0.