Cross Site Scripting Vulnerability in Control iD RH Product by Control iD
CVE-2025-2124

5.1MEDIUM

Key Information:

Vendor

Control Id

Status
Vendor
CVE Published:
9 March 2025

What is CVE-2025-2124?

A cross site scripting vulnerability exists in the Control iD RH product version 25.2.25.0, specifically within the API Handler's change_password function. This flaw allows attackers to manipulate the 'message' argument, potentially enabling remote attacks. The public disclosure of this exploit raises serious concerns for users and organizations relying on this software, given the lack of response from the vendor after informing them of the issue. As a result, users are advised to stay vigilant and implement necessary security measures.

Affected Version(s)

RH iD 25.2.25.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

y4g0 (VulDB User)
.