CVE-2025-47189: XSS
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error data of certain user flows, a different vulnerability than CVE-2025-54392.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47189?
CVE-2025-47189 is classified as a vulnerability that allows cross-site scripting (XSS) in Netwrix Directory Manager.
How do I fix CVE-2025-47189?
To remediate CVE-2025-47189, users should update to a version of Netwrix Directory Manager that is released after May 1, 2025.
What versions of Netwrix Directory Manager are affected by CVE-2025-47189?
CVE-2025-47189 affects all versions of Netwrix Directory Manager up to and including 2025-05-01.
What are the potential impacts of CVE-2025-47189?
The vulnerability could allow an attacker to execute arbitrary scripts in the context of another user, compromising their data integrity.
Is there a workaround for CVE-2025-47189 until a patch is applied?
There are no specific workarounds for CVE-2025-47189, so it is recommended to apply the security update as soon as possible.