Improper neutralization of input during web page...
Moderate severity
Unreviewed
Published
Dec 15, 2025
to the GitHub Advisory Database
•
Updated Dec 15, 2025
Description
Published by the National Vulnerability Database
Dec 15, 2025
Published to the GitHub Advisory Database
Dec 15, 2025
Last updated
Dec 15, 2025
Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to render HTML tags within a user’s browser via the integration package upload functionality. This issue is related to ESA-2025-17 (CVE-2025-25018) bypassing that fix to achieve HTML injection.
References