A cross-site scripting vulnerability exists in AVEVA PI Web API version 2023
SP1 and prior that, if exploited, could allow an authenticated attacker
(with privileges to create/update annotations or upload media files) to
persist arbitrary JavaScript code that will be executed by users who
were socially engineered to disable content security policy protections
while rendering annotation attachments from within a web browser.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Jun 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 12 Jun 2025 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A cross-site scripting vulnerability exists in AVEVA PI Web API version 2023 SP1 and prior that, if exploited, could allow an authenticated attacker (with privileges to create/update annotations or upload media files) to persist arbitrary JavaScript code that will be executed by users who were socially engineered to disable content security policy protections while rendering annotation attachments from within a web browser. | |
Title | AVEVA PI Web API Cross-site Scripting | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: icscert
Published: 2025-06-12T19:42:27.001Z
Updated: 2025-06-12T20:09:34.976Z
Reserved: 2025-03-24T16:30:31.847Z
Link: CVE-2025-2745

Updated: 2025-06-12T20:09:24.567Z

Status : Awaiting Analysis
Published: 2025-06-12T20:15:21.040
Modified: 2025-06-16T12:32:18.840
Link: CVE-2025-2745

No data.