Radware AlteonOS Web UI Management Authenticated Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in the Administrative interface of Radware AlteonOS Web UI Management version 33.0.4.50. This vulnerability allows authenticated attackers to execute arbitrary web scripts or HTML by injecting a crafted payload into the Description parameter of the AppShape++ Script Panel.

Impact

Exploitation of this vulnerability allows for the execution of arbitrary JavaScript code in the context of the user interface.

Reproduction

To reproduce this vulnerability, an authenticated user with AppShape++ Script privileges must inject a payload, such as an image tag with an onclick event, into the Description parameter of the AppShape++ Script Panel. Once the payload is inserted, it can be triggered, executing the injected script.

Added: Oct 1, 2025, 8:27 PM
Updated: Oct 1, 2025, 8:27 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.4
exploitability
5.9
remediation
0.0
relevance
0.6
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.