CVE-2025-27706 is a cross-site scripting vulnerability in the management
console of Absolute Secure Access prior to version 13.54. Attackers
with system administrator permissions can interfere with another system
administrator’s use of the management console when the second
administrator visits the page. Attack complexity is low, there are no
preexisting attack requirements, privileges required are high and active
user interaction is required. There is no impact on confidentiality,
the impact on integrity is low and there is no impact on availability.
References
Link | Resource |
---|---|
https://www.absolute.com/platform/vulnerability-archive/cve-2025-27706 | Vendor Advisory |
Configurations
History
04 Jun 2025, 19:59
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:* | |
First Time |
Absolute secure Access
Absolute |
|
References | () https://www.absolute.com/platform/vulnerability-archive/cve-2025-27706 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.4 |
Summary |
|
29 May 2025, 00:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-79 |
28 May 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-28 21:15
Updated : 2025-06-04 19:59
NVD link : CVE-2025-27706
Mitre link : CVE-2025-27706
CVE.ORG link : CVE-2025-27706
JSON object : View
Products Affected
absolute
- secure_access
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')