CVE-2025-52219

SelectZero SelectZero Data Observability Platform before 2025.5.2 contains an Open Redirect vulnerability. Legacy UI fields can be used to create arbitrary external links via HTML Injection.
References
Link Resource
https://selectzero.io/change-log/ Release Notes
Configurations

Configuration 1 (hide)

cpe:2.3:a:selectzero:selectzero:*:*:*:*:*:*:*:*

History

09 Sep 2025, 18:56

Type Values Removed Values Added
First Time Selectzero selectzero
Selectzero
CPE cpe:2.3:a:selectzero:selectzero:*:*:*:*:*:*:*:*
References () https://selectzero.io/change-log/ - () https://selectzero.io/change-log/ - Release Notes

29 Aug 2025, 16:22

Type Values Removed Values Added
Summary
  • (es) SelectZero. SelectZero Data Observability Platform anterior a la versión 2025.5.2 contiene una vulnerabilidad de redirección abierta. Los campos de la interfaz de usuario heredados pueden usarse para crear enlaces externos arbitrarios mediante inyección HTML.

26 Aug 2025, 16:15

Type Values Removed Values Added
CWE CWE-601
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

26 Aug 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-26 15:15

Updated : 2025-09-09 18:56


NVD link : CVE-2025-52219

Mitre link : CVE-2025-52219

CVE.ORG link : CVE-2025-52219


JSON object : View

Products Affected

selectzero

  • selectzero
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')