CVE-2025-47852: XSS
Published May 20, 2025
·Updated
In JetBrains TeamCity before 2025.03.2 stored XSS via YouTrack integration was possible
Affected Software
2 affected components
JetBrains TeamCity<2025.03.2
JetBrains TeamCity<2025.03.2
Event History
May 20, 2025
CVE Published
via MITRE·05:37 PM
Data Sourced
via MITRE·05:37 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-47852?
CVE-2025-47852 has been classified as a high severity vulnerability due to its potential for stored XSS attacks in JetBrains TeamCity.
2
How do I fix CVE-2025-47852?
To fix CVE-2025-47852, upgrade JetBrains TeamCity to version 2025.03.2 or later.
3
What systems are affected by CVE-2025-47852?
CVE-2025-47852 affects JetBrains TeamCity versions prior to 2025.03.2.
4
What type of vulnerability is CVE-2025-47852?
CVE-2025-47852 is a stored cross-site scripting (XSS) vulnerability.
5
Is the stored XSS in CVE-2025-47852 easy to exploit?
Yes, the stored XSS vulnerability in CVE-2025-47852 can be exploited easily if proper security measures are not implemented.