Stored Cross-Site Scripting Vulnerability in OpenZiti Admin Panel
CVE-2025-27500
What is CVE-2025-27500?
An unauthenticated endpoint on OpenZiti's admin panel allows file uploads via an HTTP POST request to the /api/upload path. This endpoint lacks proper authentication measures, enabling potential malicious actors to upload files with harmful code. If users access these files, it can lead to a stored cross-site scripting attack, compromising user sessions and sensitive information. This vulnerability has been addressed in version 3.7.1, which disables the insecure upload functionality as the application transitions from a node server architecture to a single page application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ziti-console < 3.7.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
