CVE-2025-10573
09.12.2025, 16:17
Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator session. User interaction is required.
Awaiting analysis
This vulnerability is currently awaiting analysis.