CVE-2025-43488
Severity CVSS v4.0:
LOW
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
23/07/2025
Last modified:
02/10/2025
Description
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could allow a bypass of the application's XSS filter by submitting untrusted characters. HP has addressed the issue in the latest software update.
Impact
Base Score 4.0
2.00
Severity 4.0
LOW
Base Score 3.x
4.80
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:hp:poly_clariti_manager:*:*:*:*:*:*:*:* | 10.12.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



