CVE-2025-22249
13.05.2025, 06:15
VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability.A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by tricking the user into clicking a malicious crafted payload URL.
Vendor | Product | Version |
---|---|---|
vmware | aria_automation | 8.18.0 |
vmware | aria_automation | 8.18.1 |
vmware | aria_automation | 8.18.1:patch1 |
vmware | cloud_foundation | 4.0 ≤ 𝑥 ≤ 5.2.1 |
vmware | telco_cloud_platform | 5.0 ≤ 𝑥 ≤ 5.0.1 |
𝑥
= Vulnerable software versions