CVE-2025-47851: XSS
Published May 20, 2025
·Updated
In JetBrains TeamCity before 2025.03.2 stored XSS via GitHub Checks Webhook was possible
Affected Software
2 affected components
JetBrains TeamCity<2025.03.2
JetBrains TeamCity<2025.03.2
Event History
May 20, 2025
CVE Published
via MITRE·05:37 PM
Data Sourced
via MITRE·05:37 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-47851?
CVE-2025-47851 has a high severity rating due to the potential for stored XSS attacks.
2
How do I fix CVE-2025-47851?
To fix CVE-2025-47851, upgrade JetBrains TeamCity to version 2025.03.2 or later.
3
What type of vulnerability is CVE-2025-47851?
CVE-2025-47851 is a stored cross-site scripting (XSS) vulnerability.
4
In which versions of JetBrains TeamCity is CVE-2025-47851 found?
CVE-2025-47851 is found in JetBrains TeamCity versions prior to 2025.03.2.
5
What could be the impact of CVE-2025-47851?
The impact of CVE-2025-47851 could allow an attacker to execute arbitrary scripts in another user's browser.