logo

Critical Ivanti EPM Vulnerability Allows Admin Session Hijacking via Stored XSS

ID: 6dbc4f37-07bb-5267-b9e6-cababe5631b0

STIX ID: report--6dbc4f37-07bb-5267-b9e6-cababe5631b0

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2025-12-10

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical unauthenticated stored XSS (CVE-2025-10573, CVSS 9.6) in Ivanti Endpoint Manager (EPM 2024 SU4 and below) allows attackers to submit malicious device scan fields to an unauthenticated API endpoint, which are stored and executed in administrators' web dashboards, enabling session hijacking and potential remote control of managed endpoints; Ivanti released a patch (2024 SU4 SR1) on December 9, 2025 and immediate upgrading is recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.