CVE-2025-57539
A stored cross-site scripting (XSS) vulnerability in the U2F Origin field of the Datacenter configuration in Proxmox Virtual Environment (PVE) 8.4 allows authenticated users to store malicious input.
Does this matter?
Lower severity and a low EPSS score (0.29%). Track it; it rarely justifies an emergency change on its own.
Description
A stored cross-site scripting (XSS) vulnerability in the U2F Origin field of the Datacenter configuration in Proxmox Virtual Environment (PVE) 8.4 allows authenticated users to store malicious input. The payload is rendered unsafely in the Web UI and executed when viewed by other users, potentially leading to session hijacking or other attacks.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.29% probability · 21th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- proxmox/virtual environment
- Source
- cve@mitre.org
References
- https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/page-2#post-792010Issue Tracking, Vendor Advisory
- https://github.com/khankishiyev-j/bug-bounty/blob/main/proxmox-xssExploit, Third Party Advisory
- https://www.youtube.com/watch?v=-wvkN-7oT5UBroken Link
- https://github.com/khankishiyev-j/bug-bounty/blob/main/proxmox-xssExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.