CVE-2025-57540: XSS
A stored cross-site scripting (XSS) vulnerability exists in the WebAuthn Relying Party field within the Datacenter configuration of Proxmox Virtual Environment (PVE) 8.4. Authenticated users can inject JavaScript code that is later executed in the browsers of users who view the configuration page, enabling client-side attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57540?
CVE-2025-57540 is considered a medium severity vulnerability due to its potential for exploitation through stored cross-site scripting.
How do I fix CVE-2025-57540?
To fix CVE-2025-57540, ensure you update Proxmox Virtual Environment to the latest patched version.
Who is affected by CVE-2025-57540?
Authenticated users of Proxmox Virtual Environment 8.4 can be affected by CVE-2025-57540 if they inject malicious JavaScript.
What type of vulnerability is CVE-2025-57540?
CVE-2025-57540 is a stored cross-site scripting (XSS) vulnerability.
What are the implications of CVE-2025-57540?
The implications of CVE-2025-57540 include the risk of executing unauthorized JavaScript in the browsers of users who view the affected configuration page.