Description
SelectZero Data Observability Platform before 2025.5.2 is vulnerable to HTML Injection. Legacy UI fields improperly handle user-supplied input, allowing injection of arbitrary HTML.
Published: 2025-08-26
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-28417 SelectZero Data Observability Platform before 2025.5.2 is vulnerable to HTML Injection. Legacy UI fields improperly handle user-supplied input, allowing injection of arbitrary HTML.
References
History

Tue, 09 Sep 2025 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Selectzero selectzero
CPEs cpe:2.3:a:selectzero:selectzero:*:*:*:*:*:*:*:*
Vendors & Products Selectzero selectzero

Wed, 27 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 27 Aug 2025 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Selectzero
Selectzero data Observability Platform
Vendors & Products Selectzero
Selectzero data Observability Platform

Tue, 26 Aug 2025 14:30:00 +0000

Type Values Removed Values Added
Description SelectZero Data Observability Platform before 2025.5.2 is vulnerable to HTML Injection. Legacy UI fields improperly handle user-supplied input, allowing injection of arbitrary HTML.
References

Subscriptions

Selectzero Data Observability Platform Selectzero
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-08-27T14:16:00.991Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-52217

cve-icon Vulnrichment

Updated: 2025-08-27T14:15:56.285Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-26T15:15:46.023

Modified: 2025-09-09T18:57:06.177

Link: CVE-2025-52217

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-08-27T11:41:40Z

Weaknesses