Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webconsole.
This issue affects Apache Felix Webconsole 4.x up to 4.9.8 and 5.x up to 5.0.8.
Users are recommended to upgrade to version 4.9.10 or 5.0.10 or higher, which fixes the issue.
CVSS
No CVSS.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2025/02/10/1 | Mailing List Third Party Advisory |
https://lists.apache.org/thread/z47jbf0rbylzd0ktfzdw9c8b5fpyl24m | Mailing List Vendor Advisory Issue Tracking |
Configurations
Configuration 1 (hide)
|
History
14 Jul 2025, 13:50
Type | Values Removed | Values Added |
---|---|---|
First Time |
Apache felix Webconsole
Apache |
|
References | () https://lists.apache.org/thread/z47jbf0rbylzd0ktfzdw9c8b5fpyl24m - Mailing List, Vendor Advisory, Issue Tracking | |
References | () http://www.openwall.com/lists/oss-security/2025/02/10/1 - Mailing List, Third Party Advisory | |
CPE | cpe:2.3:a:apache:felix_webconsole:*:*:*:*:*:*:*:* |
10 Feb 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
CWE |
10 Feb 2025, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-10 12:15
Updated : 2025-07-14 13:50
NVD link : CVE-2025-25247
Mitre link : CVE-2025-25247
JSON object : View
Products Affected
apache
- felix_webconsole
CWE
No CWE.