CVE-2025-22465
08.04.2025, 15:15
Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to execute arbitrary javascript in a victim's browser. Unlikely user interaction is required.
Vendor | Product | Version |
---|---|---|
ivanti | endpoint_manager | 𝑥 < 2022 |
𝑥
= Vulnerable software versions