CVE-2025-10573
EUVD-2025-20230009.12.2025, 16:17
Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator session. User interaction is required.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ivanti | endpoint_manager | 𝑥 < 2024 |
𝑥
= Vulnerable software versions
Vulnerability Media Exposure