VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to steal cookies or redirect to malicious websites.
Metrics
Affected Vendors & Products
References
History
Tue, 20 May 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 20 May 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to steal cookies or redirect to malicious websites. | |
Title | VMware ESXi and vCenter Server Reflected Cross Site Scripting (XSS) Vulnerability | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: vmware
Published: 2025-05-20T14:24:34.436Z
Updated: 2025-05-20T15:33:37.635Z
Reserved: 2025-04-16T09:29:46.972Z
Link: CVE-2025-41228

Updated: 2025-05-20T15:33:31.176Z

Status : Awaiting Analysis
Published: 2025-05-20T15:16:07.943
Modified: 2025-05-21T20:25:16.407
Link: CVE-2025-41228

No data.