Stored XSS Vulnerability in BLU-IC2 and BLU-IC4 Products by Azure Access
CVE-2025-12001
10CRITICAL
What is CVE-2025-12001?
A security vulnerability has been identified in the BLU-IC2 and BLU-IC4 products from Azure Access due to inadequate sanitation in application manifests. This flaw could allow attackers to execute stored XSS attacks, potentially compromising user data and application integrity. Users are encouraged to upgrade to secure versions to mitigate risks associated with this vulnerability.
Affected Version(s)
BLU-IC2 0 <= 1.19.5
BLU-IC4 0 <= 1.19.5
References
CVSS V4
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Kevin Schaller
Benjamin Lafois
Alexi Bitsios
Sebastian Toscano
Dominik Schneider