Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webconsole.
This issue affects Apache Felix Webconsole 4.x up to 4.9.8 and 5.x up to 5.0.8.
Users are recommended to upgrade to version 4.9.10 or 5.0.10 or higher, which fixes the issue.
References
Link | Resource |
---|---|
https://lists.apache.org/thread/z47jbf0rbylzd0ktfzdw9c8b5fpyl24m | Mailing List Vendor Advisory Issue Tracking |
http://www.openwall.com/lists/oss-security/2025/02/10/1 | Mailing List Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
14 Jul 2025, 13:50
Type | Values Removed | Values Added |
---|---|---|
References | () https://lists.apache.org/thread/z47jbf0rbylzd0ktfzdw9c8b5fpyl24m - Mailing List, Vendor Advisory, Issue Tracking | |
References | () http://www.openwall.com/lists/oss-security/2025/02/10/1 - Mailing List, Third Party Advisory | |
First Time |
Apache
Apache felix Webconsole |
|
Summary |
|
|
CPE | cpe:2.3:a:apache:felix_webconsole:*:*:*:*:*:*:*:* |
10 Feb 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
10 Feb 2025, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-10 12:15
Updated : 2025-07-14 13:50
NVD link : CVE-2025-25247
Mitre link : CVE-2025-25247
CVE.ORG link : CVE-2025-25247
JSON object : View
Products Affected
apache
- felix_webconsole
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')