Unrated severityNVD Advisory· Published Nov 3, 2025· Updated Feb 26, 2026
Incorrect Content Type Cross-Site Scripting Vulnerability
CVE-2025-10280
Description
IdentityIQ 8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and all 8.3 patch levels including 8.3p5, and all prior versions allows some IdentityIQ web services that provide non-HTML content to be accessed via a URL path that will set the Content-Type to HTML allowing a requesting browser to interpret content not properly escaped to prevent Cross-Site Scripting (XSS).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<=8.5+ 1 more
- (no CPE)range: <=8.5
- (no CPE)range: 8.5
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.