CVE-2025-40902: HTML injection in Users in Guardian/CMC before 26.1.0
A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can create a malicious user whose username contains HTML tags. When a victim attempts to delete a group containing the affected user, the injected HTML renders in their browser, enabling phishing and possibly open redirect attacks. Full XSS exploitation and direct information disclosure are prevented by the existing input validation and Content Security Policy configuration.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40902?
CVE-2025-40902 is classified as a moderate severity vulnerability due to the possibility of HTML injection.
How do I fix CVE-2025-40902?
To fix CVE-2025-40902, upgrade your Guardian/CMC software to version 26.1.0 or later.
Who is affected by CVE-2025-40902?
CVE-2025-40902 affects users with administrative privileges using Guardian/CMC versions prior to 26.1.0.
What systems are impacted by CVE-2025-40902?
The impacted systems are those running Guardian/CMC versions before 26.1.0.
Can CVE-2025-40902 be exploited by non-authenticated users?
No, CVE-2025-40902 requires an authenticated user with administrative privileges to exploit the vulnerability.