CVE-2025-22219
CVSS 3.1 Score 6.8 of 10 (medium)
Details
Published Jan 30, 2025
Summary
CVE-2025-22219 is a stored cross-site scripting (XSS) vulnerability affecting VMware Aria Operations for Logs. A malicious actor, even without administrative privileges, can inject malicious scripts into the application. This XSS vulnerability poses a serious threat, as the injected code can be executed in the context of an administrator user, potentially granting the attacker arbitrary operations within the system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- VMware Inc.