We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-41228

VMware ESXi and vCenter Server Reflected Cross Site Scripting (XSS) Vulnerability



Description

VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to steal cookies or redirect to malicious websites.

Reserved 2025-04-16 | Published 2025-05-20 | Updated 2025-05-20 | Assigner vmware


MEDIUM: 4.3CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Problem types

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Product status

Default status
unaffected

8.0 before 8.0 U3e
affected

Default status
unaffected

5.x, 4.5.x
affected

Default status
unaffected

5.x, 4.x, 3.x, 2.x
affected

Default status
unaffected

3.x,2.x
affected

Default status
unaffected

8.0 before ESXi80U3se-24659227
affected

7.0 before ESXi70U3sv-24723868
affected

References

support.broadcom.com/...l/content/SecurityAdvisories/0/25717

cve.org (CVE-2025-41228)

nvd.nist.gov (CVE-2025-41228)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-41228

Support options

Helpdesk Chat, Email, Knowledgebase