CVE-2025-2745
Severity CVSS v4.0:
MEDIUM
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
12/06/2025
Last modified:
16/06/2025
Description
A cross-site scripting vulnerability exists in AVEVA PI Web API version 2023 <br />
SP1 and prior that, if exploited, could allow an authenticated attacker <br />
(with privileges to create/update annotations or upload media files) to <br />
persist arbitrary JavaScript code that will be executed by users who <br />
were socially engineered to disable content security policy protections <br />
while rendering annotation attachments from within a web browser.
Impact
Base Score 4.0
4.50
Severity 4.0
MEDIUM
Base Score 3.x
6.50
Severity 3.x
MEDIUM