CVE-2025-1888

CVSS 3.1 Score 4.6 of 10 (medium)

Details

Published Mar 14, 2025
CWE ID 79

Summary

CVE-2025-1888 is a reflected cross-site scripting (XSS) vulnerability affecting the Leica Web Viewer component in the Aperio Eslide Manager Application. An authenticated user can exploit this issue by injecting malicious JavaScript into the "memo" field associated with a slide. The hover over action of the Microsoft Tool Tip function allows the user to view the memo and subsequently execute the malicious code. This vulnerability poses a significant risk as it can lead to unintended execution of malicious scripts and potential data breaches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share