Stored Cross-Site Scripting Vulnerability in Proxmox Virtual Environment
CVE-2025-57538

5.4MEDIUM

Key Information:

Vendor

Proxmox

Vendor
CVE Published:
9 September 2025

What is CVE-2025-57538?

A stored cross-site scripting vulnerability exists in the HTTP Proxy field of the Datacenter configuration panel in Proxmox Virtual Environment (PVE) 8.4. This flaw allows an authenticated user to input malicious scripts, which are then stored and executed in the browsers of other users accessing the vulnerable configuration page. Exploiting this vulnerability could allow attackers to run arbitrary JavaScript in the context of authenticated sessions, putting sensitive user data at risk.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.