Code Injection in CyberArk Endpoint Privilege Manager SaaS Application
CVE-2025-22272
2.1LOW
What is CVE-2025-22272?
A code injection vulnerability exists in the '/EPMUI/ModalDlgHandler.ashx?value=showReadonlyDlg' endpoint of CyberArk Endpoint Privilege Manager. By manipulating the 'modalDlgMsgInternal' parameter through a POST request, an attacker can potentially inject code that gets executed in the user's browser. Although the impact of this vulnerability is somewhat mitigated by the need to bypass the Content-Security-Policy, it still poses a risk as it could lead to unauthorized actions or data exposure. Details about other affected versions remain unclear due to lack of communication from the vendor.
Affected Version(s)
Endpoint Privilege Manager SaaS 24.7.1
References
CVSS V4
Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Karol Mazurek (Afine Team)
Maksymilian Kubiak (Afine Team)