HTML Injection Vulnerability in IBM Aspera Shares
CVE-2025-66486

4.8MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
1 April 2026

What is CVE-2025-66486?

IBM Aspera Shares versions 1.9.9 to 1.11.0 are vulnerable to an HTML injection issue that allows attackers to insert malicious HTML code. When executed, this code operates within the web browser's context of the affected site, potentially leading to harmful impacts on users. It is crucial for administrators to apply patches and security measures to mitigate the risks posed by this vulnerability.

Affected Version(s)

Aspera Shares 1.9.9 <= 1.11.0

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.