CVE-2025-43486
MEDIUMPoly Clariti Manager <10.12.1 - XSS
Title source: llmDescription
A potential stored cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The website allows user input to be stored and rendered without proper sanitization. HP has addressed the issue in the latest software update.
Scores
CVSS v3
4.8
EPSS
0.0001
EPSS Percentile
3.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
published
Affected Products (1)
hp/poly_clariti_manager
< 10.12.2
Timeline
Published
Jul 23, 2025
Tracked Since
Feb 18, 2026