Code Injection in CyberArk Endpoint Privilege Manager SaaS Application
CVE-2025-22272

2.1LOW

Key Information:

Vendor

Cyberark

Vendor
CVE Published:
28 February 2025

What is CVE-2025-22272?

A code injection vulnerability exists in the '/EPMUI/ModalDlgHandler.ashx?value=showReadonlyDlg' endpoint of CyberArk Endpoint Privilege Manager. By manipulating the 'modalDlgMsgInternal' parameter through a POST request, an attacker can potentially inject code that gets executed in the user's browser. Although the impact of this vulnerability is somewhat mitigated by the need to bypass the Content-Security-Policy, it still poses a risk as it could lead to unauthorized actions or data exposure. Details about other affected versions remain unclear due to lack of communication from the vendor.

Affected Version(s)

Endpoint Privilege Manager SaaS 24.7.1

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Karol Mazurek (Afine Team)
Maksymilian Kubiak (Afine Team)
.