Vulnerability Description
A stored cross-site scripting (XSS) vulnerability exists in the WebAuthn Relying Party field within the Datacenter configuration of Proxmox Virtual Environment (PVE) 8.4. Authenticated users can inject JavaScript code that is later executed in the browsers of users who view the configuration page, enabling client-side attacks.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Proxmox | Virtual Environment | 8.4 |
Related Weaknesses (CWE)
References
- https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisorieIssue TrackingVendor Advisory
- https://github.com/khankishiyev-j/bug-bounty/blob/main/proxmox-xssExploitThird Party Advisory
- https://www.youtube.com/watch?v=-wvkN-7oT5UBroken Link
- https://github.com/khankishiyev-j/bug-bounty/blob/main/proxmox-xssExploitThird Party Advisory
FAQ
What is CVE-2025-57540?
CVE-2025-57540 is a vulnerability with a CVSS score of 5.4 (MEDIUM). A stored cross-site scripting (XSS) vulnerability exists in the WebAuthn Relying Party field within the Datacenter configuration of Proxmox Virtual Environment (PVE) 8.4. Authenticated users can injec...
How severe is CVE-2025-57540?
CVE-2025-57540 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-57540?
Check the references section above for vendor advisories and patch information. Affected products include: Proxmox Virtual Environment.