CVE-2025-8386
MEDIUMAVEVA Application Server - Authenticated XSS via App Objects Help Files
Title source: llmDescription
The vulnerability, if exploited, could allow an authenticated miscreant (with privilege of "aaConfigTools") to tamper with App Objects' help files and persist a cross-site scripting (XSS) injection that when executed by a victim user, can result in horizontal or vertical escalation of privileges. The vulnerability can only be exploited during config-time operations within the IDE component of Application Server. Run-time components and operations are not affected.
Scores
CVSS v3
6.9
EPSS
0.0001
EPSS Percentile
3.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-80
Status
published
Products (1)
AVEVA/Application Server
< Versions 2023 R2 SP1 P02
Published
Nov 15, 2025
Tracked Since
Feb 18, 2026