CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.6. It affects Java, Ivanti. Its EPSS score suggests a 30.5% probability of exploitation in the next 30 days. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.
CVE
CVE-2025-10573
Severity
CRITICAL
CVSS
9.6
EPSS
30.53%
Java Ivanti
Original NVD Description
Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator session. User interaction is required.
Related CVEs
Other vulnerabilities affecting the same vendor(s)