CyberSec.Space Logo
返回 CVE 浏览器

CVE-2025-55672

MEDIUM
5.3
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2025-08-14
Last Modified2026-06-17
Data SourcesNVD

Vulnerability Description

A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit charts can inject a malicious payload into a column's label. The payload is not properly sanitized and gets executed in the victim's browser when they hover over the chart, potentially leading to session hijacking or the execution of arbitrary commands on behalf of the user. This issue affects Apache Superset: before 5.0.0. Users are recommended to upgrade to version 5.0.0, which fixes the issue.

Affected Platforms (CPE)

📦
Apache

Superset

< 5.0.0

References & Advisories

相关漏洞威胁