CVE 9.3 CRITICAL

spacewalk-java has various XSS issues on search page_CVE-2025-53883

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H

Description

A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability allows attackers to run arbitrary javascript via a reflected XSS issue in the search fields.This issue affects Container suse/manager/5.0/x86_64/server:latest: from ? before 5.0.28-150600.3.36.8; SUSE Manager Server LTS 4.3: from ? before 4.3.88-150400.3.113.5.

AI Analysis

A reflected XSS issue in the search fields of SUSE Manager Server allows attackers to run arbitrary javascript

Basic Information

ID CVE-2025-53883
Source suse
Published Oct 30, 2025 at 10:50
Modified Oct 30, 2025 at 13:16

Affected Product

Vendor SUSE
Product Container suse manager 5.0
Affected Versions SUSE Container suse manager 5.0 0
SUSE SUSE Manager Server LTS 4.3 0

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor SUSE
Product SUSE Manager Server
Version before 5.0.28-150600.3.36.8, before 4.3.88-150400.3.113.5

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.