CVE-2025-2745
Last modified
CVE-2025-2745 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A cross-site scripting vulnerability exists in AVEVA PI Web API version 2023 SP1 and prior that, if exploited, could allow an authenticated attacker (with privileges to create/update annotations or upload media files) to persist arbitrary JavaScript code that will be executed by users who were socially engineered to disable content security policy protections while rendering annotation attachments from within a web browser.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
A cross-site scripting vulnerability exists in AVEVA PI Web API version 2023 SP1 and prior that, if exploited, could allow an authenticated attacker (with privileges to create/update annotations or upload media files) to persist arbitrary JavaScript code that will be executed by users who were socially engineered to disable content security policy protections while rendering annotation attachments from within a web browser.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:N
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-2745?
How severe is CVE-2025-2745?
How do I fix CVE-2025-2745?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-27444A reflected XSS vulnerability in RSform!Pro component 3.0.0 …4.8
- CVE-2025-27445A path traversal vulnerability in RSFirewall component 2.9.7…5.4
- CVE-2025-27446Incorrect Permission Assignment for Critical Resource vulner…7.8
- CVE-2025-27447The web application is susceptible to cross-site-scripting a…6.1
- CVE-2025-27448The web application is susceptible to cross-site-scripting a…5.4
- CVE-2025-27449The MEAC300-FNADE4 does not implement sufficient measures to…9.8
- CVE-2025-27450The Secure attribute is missing on multiple cookies provided…6.5
- CVE-2025-27451For failed login attempts, the application returns different…5.3
- CVE-2025-27452The configuration of the Apache httpd webserver which serves…7.5
- CVE-2025-27453The HttpOnly flag is set to false on the PHPSESSION cookie. …6.5
- CVE-2025-27454The application is vulnerable to cross-site request forgery.…4.3
- CVE-2025-27455The web application is vulnerable to clickjacking attacks. T…6.1
Are you affected by CVE-2025-2745?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
