Stored Cross-Site Scripting Vulnerability in Proxmox Virtual Environment
CVE-2025-57540

5.4MEDIUM

Key Information:

Vendor

Proxmox

Vendor
CVE Published:
9 September 2025

What is CVE-2025-57540?

A stored cross-site scripting (XSS) vulnerability has been identified in the WebAuthn Relying Party field of Proxmox Virtual Environment (PVE) 8.4. This flaw allows authenticated users to inject malicious JavaScript code, which is subsequently executed in the browsers of anyone viewing the configuration page. This exposes users to potential client-side attacks, thereby compromising the security and integrity of their data. Proper validation and sanitization methods should be implemented to mitigate the risk of such vulnerabilities.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.