CVE-2025-2745

A cross-site scripting vulnerability exists in AVEVAPI Web API version 2023 
SP1 and prior that, if exploited, could allow an authenticated attacker 
(with privileges to create/update annotations or upload media files) to 
persist arbitrary JavaScript code that will be executed by users who 
were socially engineered to disable content security policy protections 
while rendering annotation attachments from within a web browser.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:N
icscertCNA
6.5 MEDIUM
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:N
CISA-ADPADP
---
---