VMware ESXi
cpe:2.3:o:vmware:esxi:*:*:*:*:*:*:*
- ~8.0
- ~7.0
A reflected cross-site scripting vulnerability has been identified in VMware ESXi and vCenter Server. This issue arises from improper input validation, allowing a malicious actor with network access to certain URL paths to exploit the vulnerability. The exploitation could lead to cookie theft or redirection to malicious websites.
Exploitation of this vulnerability could result in reflected cross-site scripting, allowing for cookie theft or redirection to malicious websites.
To address this vulnerability, users should apply the updates listed in the 'Fixed Version' column of the 'Response Matrix' in the VMware security advisory VMSA-2025-0010.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.