CVE-2025-23057

A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary script code in a victim's web browser within the context of the compromised interface.
Configurations

Configuration 1 (hide)

cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*

History

28 Mar 2025, 19:03

Type Values Removed Values Added
References () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04775en_us&docLocale=en_US - () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04775en_us&docLocale=en_US - Vendor Advisory
CPE cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
First Time Arubanetworks
Arubanetworks fabric Composer

13 Mar 2025, 15:15

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad en la interfaz de administración web de HPE Aruba Networking Fabric Composer podría permitir que un atacante remoto autenticado realice un ataque Cross-Site Scripting (XSS) Almacenado. Si se aprovecha con éxito, un actor de amenazas podría ejecutar código script arbitrario en el navegador web de una víctima dentro del contexto de la interfaz comprometida.
CWE CWE-79

28 Jan 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-28 18:15

Updated : 2025-03-28 19:03


NVD link : CVE-2025-23057

Mitre link : CVE-2025-23057

CVE.ORG link : CVE-2025-23057


JSON object : View

Products Affected

arubanetworks

  • fabric_composer
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')