Feed/CVE-2025-8386
CVE-2025-8386MEDIUMCVSS 6.9

CVE-2025-8386

Published Nov 14, 2025·Updated Jun 17, 2026

NVD Description

The vulnerability, if exploited, could allow an authenticated miscreant (with privilege of "aaConfigTools") to tamper with App Objects' help files and persist a cross-site scripting (XSS) injection that when executed by a victim user, can result in horizontal or vertical escalation of privileges. The vulnerability can only be exploited during config-time operations within the IDE component of Application Server. Run-time components and operations are not affected.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free