VYPR
Unrated severityNVD Advisory· Published Apr 1, 2025· Updated Apr 7, 2025

Cross-site Scripting (Stored)

CVE-2025-1534

Description

CVE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Payara Platform Payara Server allows : Remote Code Inclusion.This issue affects Payara Server: from 4.1.2.1919.1 before 4.1.2.191.51, from 5.20.0 before 5.68.0, from 6.0.0 before 6.23.0, from 6.2022.1 before 6.2025.2.

Affected products

2
  • Payara Platform/Payara Serverllm-fuzzy2 versions
    >=4.1.2.1919.1, <4.1.2.191.51; >=5.20.0, <5.68.0; >=6.0.0, <6.23.0; >=6.2022.1, <6.2025.2+ 1 more
    • (no CPE)range: >=4.1.2.1919.1, <4.1.2.191.51; >=5.20.0, <5.68.0; >=6.0.0, <6.23.0; >=6.2022.1, <6.2025.2
    • (no CPE)range: 4.1.2.1919.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.