CVE 4.6 MEDIUM

Software Acquisition Guide Supplier Response Web Tool XSS_CVE-2025-67634

4.6 / 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Description

The CISA Software Acquisition Guide Supplier Response Web Tool before 2025-12-11 was vulnerable to cross-site scripting via text fields. If an attacker could convince a user to import a specially-crafted JSON file, the Tool would load JavaScript from the file into the page. The JavaScript would execute in the context of the user's browser when the user submits the page (clicks 'Next').

Basic Information

ID CVE-2025-67634
Source cisa-cg
Published Dec 12, 2025 at 20:36

Affected Product

Vendor CISA
Product Software Acquisition Guide Tool
Affected Versions CISA Software Acquisition Guide Tool 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.