CVE-2025-22219

CVSS 3.1 Score 6.8 of 10 (medium)

Details

Published Jan 30, 2025

Summary

CVE-2025-22219 is a stored cross-site scripting (XSS) vulnerability affecting VMware Aria Operations for Logs. A malicious actor, even without administrative privileges, can inject malicious scripts into the application. This XSS vulnerability poses a serious threat, as the injected code can be executed in the context of an administrator user, potentially granting the attacker arbitrary operations within the system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share