The vulnerability, if exploited, could allow an authenticated miscreant
(with privilege of "aaConfigTools") to tamper with App Objects' help
files and persist a cross-site scripting (XSS) injection that when
executed by a victim user, can result in horizontal or vertical
escalation of privileges. The vulnerability can only be exploited during
config-time operations within the IDE component of Application Server.
Run-time components and operations are not affected.
Metrics
Affected Vendors & Products
References
History
Sat, 15 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aveva
Aveva application Server |
|
| Vendors & Products |
Aveva
Aveva application Server |
Sat, 15 Nov 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The vulnerability, if exploited, could allow an authenticated miscreant (with privilege of "aaConfigTools") to tamper with App Objects' help files and persist a cross-site scripting (XSS) injection that when executed by a victim user, can result in horizontal or vertical escalation of privileges. The vulnerability can only be exploited during config-time operations within the IDE component of Application Server. Run-time components and operations are not affected. | |
| Title | AVEVA Application Server IDE Basic Cross-site Scripting | |
| Weaknesses | CWE-80 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published: 2025-11-14T23:57:04.396Z
Updated: 2025-11-14T23:57:04.396Z
Reserved: 2025-07-30T18:49:26.187Z
Link: CVE-2025-8386
No data.
Status : Received
Published: 2025-11-15T00:15:48.290
Modified: 2025-11-15T00:15:48.290
Link: CVE-2025-8386
No data.