THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-23169 (MEDIUM 6.1) — The Versa Director SD-WAN orchestration platform allows customization of the user interface, including the header, footer, and logo. However, the input provided for these customizations is not properly validated or sanitized, allowing a malicious user to inject and store cross-si

[NVD] CVE-2025-23169 (MEDIUM 6.1) — The Versa Director SD-WAN orchestration platform allows customization of the user interface, including the header, footer, and logo. However, the input provided for these customizations is not properly validated or sanitized, allowing a malicious user to inject and store cross-si

lownvdPublished 2025-06-19

CVE-2025-23169 CVSS: 6.1 MEDIUM Published: 2025-06-19T00:15:21.497

The Versa Director SD-WAN orchestration platform allows customization of the user interface, including the header, footer, and logo. However, the input provided for these customizations is not properly validated or sanitized, allowing a malicious user to inject and store cross-site scripting (XSS) payloads.

Exploitation Status

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-23169