Stored Cross-Site Scripting Vulnerability in Proxmox Virtual Environment
CVE-2025-57540
5.4MEDIUM
What is CVE-2025-57540?
A stored cross-site scripting (XSS) vulnerability has been identified in the WebAuthn Relying Party field of Proxmox Virtual Environment (PVE) 8.4. This flaw allows authenticated users to inject malicious JavaScript code, which is subsequently executed in the browsers of anyone viewing the configuration page. This exposes users to potential client-side attacks, thereby compromising the security and integrity of their data. Proper validation and sanitization methods should be implemented to mitigate the risk of such vulnerabilities.
