VE-2025-27706 is a cross-site scripting vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with system administrator permissions can interfere with another system administrator’s use of the management console when the second administrator visits the page. Attack complexity is low, there are no preexisting attack requirements, privileges required are high and active user interaction is required. There is no impact on confidentiality, the impact on integrity is low and there is no impact on availability.
| Link | Resource |
|---|---|
| https://www.absolute.com/platform/vulnerability-archive/cve-2025-27706 | Vendor Advisory |
04 Jun 2025, 19:59
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.absolute.com/platform/vulnerability-archive/cve-2025-27706 - Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.4 |
| Summary |
|
|
| First Time |
Absolute secure Access
Absolute |
|
| CPE | cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:* |
29 May 2025, 00:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-79 |
28 May 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2025-05-28 21:15
Updated : 2025-06-04 19:59
NVD link : CVE-2025-27706
Mitre link : CVE-2025-27706
CVE.ORG link : CVE-2025-27706
JSON object : View
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')