Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webconsole.
This issue affects Apache Felix Webconsole 4.x up to 4.9.8 and 5.x up to 5.0.8.
Users are recommended to upgrade to version 4.9.10 or 5.0.10 or higher, which fixes the issue.
CVE ID: CVE-2025-25247
Vendor: Apache Software Foundation
Product: Apache Felix Webconsole
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 11.88% (scored less or equal to compared to others)
EPSS Date: 2025-03-11 (when was this score calculated)