CVE-2025-23366

A flaw was found in the HAL Console in the Wildfly component, which does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a web page that is served to other users. The attacker must be authenticated as a user that belongs to management groups “SuperUser”, “Admin”, or “Maintainer”.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:hal_management_console:*:*:*:*:*:*:*:*

History

14 Oct 2025, 17:54

Type Values Removed Values Added
Summary
  • (es) Se encontró un fallo en la consola HAL del componente Wildfly, que no neutraliza o neutraliza incorrectamente la entrada controlable por el usuario antes de colocarla en la salida utilizada como una página web que se muestra a otros usuarios. El atacante debe estar autenticado como un usuario que pertenece a los grupos de administración “SuperUser”, “Admin” o “Maintainer”.
CPE cpe:2.3:a:redhat:hal_management_console:*:*:*:*:*:*:*:*
First Time Redhat
Redhat hal Management Console
References () https://access.redhat.com/security/cve/CVE-2025-23366 - () https://access.redhat.com/security/cve/CVE-2025-23366 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2337619 - () https://bugzilla.redhat.com/show_bug.cgi?id=2337619 - Vendor Advisory

14 Jan 2025, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-14 18:16

Updated : 2025-10-14 17:54


NVD link : CVE-2025-23366

Mitre link : CVE-2025-23366

CVE.ORG link : CVE-2025-23366


JSON object : View

Products Affected

redhat

  • hal_management_console
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')