Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Critical Ivanti EPM Vulnerability Allows Admin Session Hijacking via Stored XSS

Posted on December 10, 2025December 11, 2025 By CWS

A critical stored cross-site scripting vulnerability in Ivanti Endpoint Manager (“EPM”) versions 2024 SU4 and below, that could enable attackers to hijack administrator sessions without authentication.

The vulnerability, identified as CVE-2025-10573, has been assigned a CVSS score of 9.6 and patched on December 9, 2025, with the release of Ivanti EPM version 2024 SU4 SR1.

An attacker with unauthenticated access to the primary EPM web service can join fake managed endpoints to the EPM server. Poisoning the administrator’s web dashboard with malicious JavaScript.

When an Ivanti EPM administrator views the contaminated dashboard during normal operations.

AttributeDetailsCVE IDCVE-2025-10573Vulnerability TypeStored Cross-Site Scripting (XSS)CVSS Score9.6Affected ProductIvanti Endpoint Manager (EPM)Affected VersionsEPM 2024 SU4 and below

The passive user interaction triggers client-side JavaScript execution, granting the attacker complete control of the administrator’s session.

The vulnerability stems from the ‘incomingdata’ web API, which processes device scan data without proper input validation.

Attackers can submit malicious payloads through this unauthenticated endpoint. These are then stored in the device database and rendered safely in the administrator dashboard interface.

An unauthenticated attacker can craft a POST request to the ‘/incomingdata/postcgi.exe’ endpoint. It contains XSS payloads embedded in device scan fields such as Device ID, Display Name, or OS Name.

These payloads are automatically processed and added to the device database without sanitization. When administrators access web dashboard pages displaying device information.

Including ‘frameset.aspx’ and ‘db_frameset.aspx’, the malicious scripts execute in their browsers.

Ivanti EPM is a widely deployed endpoint management software used by organizations for remote administration, vulnerability scanning, and compliance management.

Successful exploitation enables attackers to remotely control endpoints and install unauthorized software, making this vulnerability particularly dangerous.

According to Rapid7, Organizations should immediately upgrade to Ivanti EPM version 2024 SU4 SR1. Because this vulnerability is unauthenticated, patching affected instances as soon as possible is critical.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Cyber Security News Tags:Admin, Critical, EPM, Hijacking, Ivanti, Session, Stored, Vulnerability, XSS

Post navigation

Previous Post: Over 644,000 Domains Exposed to Critical React Server Components Vulnerability
Next Post: .NET SOAPwn Flaw Opens Door for File Writes and Remote Code Execution via Rogue WSDL

Related Posts

81% Router Usres Have Not Changed Default Admin Passwords, Exposing Devices to Hackers Cyber Security News
Lucid PhaaS With 17,500 Phishing Domains Mimics 316 Brands From 74 Countries Cyber Security News
New EtherHiding Attack Uses Web-Based Attacks to Deliver Malware and Rotate Payloads Cyber Security News
VMware Tools and Aria Operations Vulnerabilities Let Attackers Escalate Privileges to Root Cyber Security News
RapperBot Hijacking Devices to Launch DDoS Attack In a Split Second Cyber Security News
Microsoft Confirms Error Entry in Windows Firewall With Advanced Security Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Office Zero-day Vulnerability Actively Exploited in Attacks
  • New Lawsuit Claims that Meta Can Read All the WhatsApp Users Messages
  • Top 10 Best VPN Services of 2026
  • Hundreds of Exposed Clawdbot Gateways Leave API Keys and Private Chats Vulnerable
  • Indian Users Targeted in Tax Phishing Campaign Delivering Blackmoon Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Office Zero-day Vulnerability Actively Exploited in Attacks
  • New Lawsuit Claims that Meta Can Read All the WhatsApp Users Messages
  • Top 10 Best VPN Services of 2026
  • Hundreds of Exposed Clawdbot Gateways Leave API Keys and Private Chats Vulnerable
  • Indian Users Targeted in Tax Phishing Campaign Delivering Blackmoon Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark