CVE-2025-32984

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Apr 25, 2025
Updated: Apr 29, 2025
CWE ID 79

Summary

CVE-2025-32984 is a stored cross-site scripting (XSS) vulnerability affecting NETSCOUT nGeniusONE versions prior to 6.4.0. An attacker can exploit this issue by injecting malicious scripts into a POST parameter, which is then stored and executed in a user's web browser when they view a crafted page. This may lead to unauthorized access to sensitive information or the ability to launch further attacks. Successful exploitation of this vulnerability relies on user interaction, making it a significant risk for organizations that use the nGeniusONE platform. It is recommended that affected users upgrade to a patched version to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share