CVE-2025-23366

Executive Summary

CVE-2025-23366 exposes an authenticated cross‑site scripting (XSS) vulnerability in the Wildfly HAL Console. The flaw allows a user with SuperUser, Admin, or Maintainer privileges to inject malicious content that is rendered in the console’s web pages and served to other users. This can lead to session hijacking, data theft, or further exploitation of the affected Wildfly environment. The issue is not yet listed in CISA KEV.


Authoritative CVE Metadata - CVSS Base Score: 6.5 (MEDIUM) - Published: 2025-01-14T18:16:06.290 - Last Modified: 2026-08-19T01:16:54.713

Original Description: A flaw was found in the HAL Console in the Wildfly component, which does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a web page that is served to other users. The attacker must be authenticated as a user that belongs to management groups “SuperUser”, “Admin”, or “Maintainer”.

"Intuition will tell the thinking mind where to look next."

— Jonas Salk
Source: NVD