CVE-2025-54392: XSS
Published Aug 7, 2025
·Updated
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error data, a different vulnerability than CVE-2025-47189.
Affected Software
2 affected components
Netwrix Directory Manager<11.1.25162.02
Netwrix Directory Manager>=11.0.0.0<11.1.25162.02
Event History
Aug 7, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-54392?
CVE-2025-54392 is considered a critical vulnerability due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2025-54392?
To fix CVE-2025-54392, upgrade to Netwrix Directory Manager version 11.1.25162.02 or later.
3
What types of attacks can CVE-2025-54392 enable?
CVE-2025-54392 can enable cross-site scripting (XSS) attacks that can compromise user authentication and data.
4
What versions of Netwrix Directory Manager are affected by CVE-2025-54392?
Netwrix Directory Manager version 11.0.0.0 and earlier are affected by CVE-2025-54392.
5
Is CVE-2025-54392 related to any other vulnerabilities?
Yes, CVE-2025-54392 is a different vulnerability than CVE-2025-47189.