Stored Cross-Site Scripting Vulnerability in Proxmox Virtual Environment
CVE-2025-57538
5.4MEDIUM
What is CVE-2025-57538?
A stored cross-site scripting vulnerability exists in the HTTP Proxy field of the Datacenter configuration panel in Proxmox Virtual Environment (PVE) 8.4. This flaw allows an authenticated user to input malicious scripts, which are then stored and executed in the browsers of other users accessing the vulnerable configuration page. Exploiting this vulnerability could allow attackers to run arbitrary JavaScript in the context of authenticated sessions, putting sensitive user data at risk.
