CVE-2025-53883: spacewalk-java has various XSS issues on search page
A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability allows attackers to run arbitrary javascript via a reflected XSS issue in the search fields.This issue affects Container suse/manager/5.0/x8664/server:latest: from ? before 5.0.28-150600.3.36.8; SUSE Manager Server LTS 4.3: from ? before 4.3.88-150400.3.113.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53883?
CVE-2025-53883 is categorized as a basic cross-site scripting (XSS) vulnerability that can allow attackers to execute arbitrary JavaScript.
How do I fix CVE-2025-53883?
To mitigate CVE-2025-53883, update the SUSE Manager Server to version 5.0.28-150600.3 or later.
What software versions are affected by CVE-2025-53883?
CVE-2025-53883 affects SUSE Manager Server versions prior to 5.0.28-150600.3 and SUSE Manager Server LTS versions prior to 4.3.88-150400.3.113.5.
Can CVE-2025-53883 be exploited remotely?
Yes, CVE-2025-53883 can be exploited remotely through the search fields, allowing malicious JavaScript to be executed.
What kind of attacks can CVE-2025-53883 facilitate?
CVE-2025-53883 can facilitate various attacks including session hijacking and data theft through cross-site scripting.