CVE-2025-43486: Poly Clariti Manager - Multiple Security Vulnerabilities
Published Jul 22, 2025
·Updated
A potential stored cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The website allows user input to be stored and rendered without proper sanitization. HP has addressed the issue in the latest software update.
Affected Software
2 affected components
Poly Clariti Manager<10.12.1
HP Poly Clariti Manager<10.12.2
Event History
Jul 22, 2025
CVE Published
via MITRE·11:21 PM
Data Sourced
via MITRE·11:21 PM
DescriptionWeakness
Jul 23, 2025
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-43486?
CVE-2025-43486 is classified as a moderate severity stored cross-site scripting vulnerability.
2
How do I fix CVE-2025-43486?
To fix CVE-2025-43486, update the Poly Clariti Manager to version 10.12.1 or later.
3
Which versions are affected by CVE-2025-43486?
CVE-2025-43486 affects all versions of Poly Clariti Manager prior to 10.12.1.
4
What kind of vulnerability is CVE-2025-43486?
CVE-2025-43486 is a stored cross-site scripting vulnerability that allows user input without proper sanitization.
5
Who is the vendor for CVE-2025-43486?
The vendor for CVE-2025-43486 is Poly, responsible for the Poly Clariti Manager software.