CVE-2025-8386: AVEVA Application Server IDE Basic Cross-site Scripting
The vulnerability, if exploited, could allow an authenticated miscreant (with privilege of "aaConfigTools") to tamper with App Objects' help files and persist a cross-site scripting (XSS) injection that when executed by a victim user, can result in horizontal or vertical escalation of privileges. The vulnerability can only be exploited during config-time operations within the IDE component of Application Server. Run-time components and operations are not affected.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8386?
CVE-2025-8386 has a medium severity rating, indicating a moderate risk to affected systems.
How do I fix CVE-2025-8386?
To fix CVE-2025-8386, upgrade to the latest version of AVEVA Application Server that addresses this vulnerability.
Who is affected by CVE-2025-8386?
CVE-2025-8386 affects users of AVEVA Application Server IDE and versions 2023 R2 SP1 P02 and prior.
What kind of attack can exploit CVE-2025-8386?
An authenticated attacker with 'aaConfigTools' privileges can exploit CVE-2025-8386 to perform cross-site scripting (XSS) attacks.
What are the potential impacts of CVE-2025-8386?
Exploitation of CVE-2025-8386 could lead to unauthorized manipulation of help files and potentially escalate privileges for victim users.