CVE-2025-10573
Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute
Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator session. User interaction is required.
CRITICAL · CVSS 9.6
EPSS 0.00058
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0