{ "data_version": "4.0", "data_type": "CVE", "data_format": "MITRE", "CVE_data_meta": { "ID": "CVE-2025-25247", "ASSIGNER": "security@apache.org", "STATE": "PUBLIC" }, "description": { "description_data": [ { "lang": "eng", "value": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webconsole.\n\nThis issue affects Apache Felix Webconsole 4.x up to 4.9.8 and 5.x up to 5.0.8.\n\nUsers are recommended to upgrade to version 4.9.10 or 5.0.10 or higher, which fixes the issue." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')", "cweId": "CWE-79" } ] } ] }, "affects": { "vendor": { "vendor_data": [ { "vendor_name": "Apache Software Foundation", "product": { "product_data": [ { "product_name": "Apache Felix Webconsole", "version": { "version_data": [ { "version_affected": "<=", "version_name": "Version 4.x", "version_value": "4.9.8" }, { "version_affected": "<=", "version_name": "Version 5.x", "version_value": "5.0.8" } ] } } ] } } ] } }, "references": { "reference_data": [ { "url": "https://lists.apache.org/thread/z47jbf0rbylzd0ktfzdw9c8b5fpyl24m", "refsource": "MISC", "name": "https://lists.apache.org/thread/z47jbf0rbylzd0ktfzdw9c8b5fpyl24m" } ] }, "generator": { "engine": "Vulnogram 0.2.0" }, "source": { "advisory": "FELIX-6751", "discovery": "UNKNOWN" }, "credits": [ { "lang": "en", "value": "Viktor Mares (me@viktormares.com)" } ] }