CVE-2025-54089 is a cross-site scripting vulnerability in versions of secure access prior to 14.10. Attackers with administrative access to the console can interfere with another administrator’s access to the console. The attack complexity is low; there are no attack requirements. Privileges required to execute the attack are high and the victim must actively participate in the attack sequence. There is no impact to confidentiality or availability, there is a low impact to integrity.
History

Thu, 02 Oct 2025 20:30:00 +0000

Type Values Removed Values Added
Description CVE-2025-54089 is a cross-site scripting vulnerability in versions of secure access prior to 14.10. Attackers with administrative access to the console can interfere with another administrator’s access to the console. The attack complexity is low; there are no attack requirements. Privileges required to execute the attack are high and the victim must actively participate in the attack sequence. There is no impact to confidentiality or availability, there is a low impact to integrity.
Title Cross-site Scripting vulnerability in Secure Access prior to 14.10
References
Metrics cvssV4_0

{'score': 4.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Absolute

Published:

Updated: 2025-10-02T20:15:09.464Z

Reserved: 2025-07-16T17:10:03.453Z

Link: CVE-2025-54089

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-02T21:16:00.860

Modified: 2025-10-02T21:16:00.860

Link: CVE-2025-54089

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.