CVE-2025-27706

Severity CVSS v4.0:
MEDIUM
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
28/05/2025
Last modified:
04/06/2025

Description

CVE-2025-27706 is a cross-site scripting vulnerability in the management<br /> console of Absolute Secure Access prior to version 13.54. Attackers <br /> with system administrator permissions can interfere with another system <br /> administrator’s use of the management console when the second <br /> administrator visits the page. Attack complexity is low, there are no <br /> preexisting attack requirements, privileges required are high and active<br /> user interaction is required. There is no impact on confidentiality, <br /> the impact on integrity is low and there is no impact on availability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:* 13.54 (excluding)