First published: Fri Apr 25 2025(Updated: )
In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab
Credit: cve@jetbrains.com
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains TeamCity | <2025.03.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-46618 is categorized as a stored cross-site scripting (XSS) vulnerability, which can pose significant security risks to affected users.
To fix CVE-2025-46618, upgrade your JetBrains TeamCity installation to version 2025.03.1 or later.
All versions of JetBrains TeamCity prior to 2025.03.1 are vulnerable to CVE-2025-46618.
CVE-2025-46618 allows attackers to execute malicious scripts in the context of the user’s browser through stored XSS.
For detailed information about CVE-2025-46618, refer to the JetBrains security updates page.