Stored Cross-Site Scripting Vulnerability in Proxmox Virtual Environment
CVE-2025-57539

5.4MEDIUM

Key Information:

Vendor

Proxmox

Vendor
CVE Published:
9 September 2025

What is CVE-2025-57539?

A stored cross-site scripting (XSS) vulnerability exists in the U2F Origin field of the Datacenter configuration in Proxmox Virtual Environment 8.4. This security issue permits authenticated users to input malicious scripts that can be stored and subsequently executed within the Web UI when viewed by other users. Such exploitation can lead to significant security breaches, including session hijacking and unauthorized access to sensitive user information.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.