CVE-2025-52217

SelectZero Data Observability Platform before 2025.5.2 is vulnerable to HTML Injection. Legacy UI fields improperly handle user-supplied input, allowing injection of arbitrary HTML.
References
Link Resource
https://selectzero.io/change-log/ Release Notes
Configurations

Configuration 1 (hide)

cpe:2.3:a:selectzero:selectzero:*:*:*:*:*:*:*:*

History

09 Sep 2025, 18:57

Type Values Removed Values Added
References () https://selectzero.io/change-log/ - () https://selectzero.io/change-log/ - Release Notes
CPE cpe:2.3:a:selectzero:selectzero:*:*:*:*:*:*:*:*
First Time Selectzero selectzero
Selectzero

27 Aug 2025, 15:15

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
Summary
  • (es) SelectZero Data Observability Platform anterior a la versión 2025.5.2 es vulnerable a la inyección de HTML. Los campos de la interfaz de usuario heredada gestionan incorrectamente la entrada proporcionada por el usuario, lo que permite la inyección de HTML arbitrario.

26 Aug 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-26 15:15

Updated : 2025-09-09 18:57


NVD link : CVE-2025-52217

Mitre link : CVE-2025-52217

CVE.ORG link : CVE-2025-52217


JSON object : View

Products Affected

selectzero

  • selectzero
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')