5.4
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Description
Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to render HTML tags within a user’s browser via the integration package upload functionality. This issue is related to ESA-2025-17 (CVE-2025-25018) bypassing that fix to achieve HTML injection.
Basic Information
ID
CVE-2025-37732
Source
elastic
Published
Dec 15, 2025 at 10:21
Affected Product
Vendor
Elastic
Product
Kibana
Version
7.0.0
Affected Versions
Elastic Kibana 7.0.0
Elastic Kibana 8.0.0
Elastic Kibana 9.0.0
Elastic Kibana 9.2.0
Elastic Kibana 8.0.0
Elastic Kibana 9.0.0
Elastic Kibana 9.2.0