Stored XSS Vulnerability in BLU-IC2 and BLU-IC4 Products by Azure Access
CVE-2025-12001

10CRITICAL

Key Information:

Vendor
CVE Published:
20 October 2025

What is CVE-2025-12001?

A security vulnerability has been identified in the BLU-IC2 and BLU-IC4 products from Azure Access due to inadequate sanitation in application manifests. This flaw could allow attackers to execute stored XSS attacks, potentially compromising user data and application integrity. Users are encouraged to upgrade to secure versions to mitigate risks associated with this vulnerability.

Affected Version(s)

BLU-IC2 0 <= 1.19.5

BLU-IC4 0 <= 1.19.5

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kevin Schaller
Benjamin Lafois
Alexi Bitsios
Sebastian Toscano
Dominik Schneider
.
CVE-2025-12001 : Stored XSS Vulnerability in BLU-IC2 and BLU-IC4 Products by Azure Access