{"id":"CVE-2025-23366","title":"A flaw was found in the HAL Console in the Wildfly component, which does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a web page that is served to other users","summary":"A flaw was found in the HAL Console in the Wildfly component, which does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a web page that is served to other users. The attacker must …","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-79"],"vendor":"redhat","product":"hal_management_console","affected":["hal_management_console < 3.7.7"],"patched":["hal_management_console 3.7.7"],"published":"2025-01-14","updated":"2026-08-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-23366","references":[{"url":"https://access.redhat.com/errata/RHSA-2025:10924","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:10925","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:10926","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2025-23366","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2337619","label":"secalert@redhat.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-23366.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-23366"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-23366"},{"url":"https://access.redhat.com/errata/RHSA-2025:10931"}],"tags":["nvd","csaf","vex","red-hat"],"epss":0.00451,"epssPercentile":0.38539,"ingestedAt":"2026-08-04T07:38:00.321Z","slug":"CVE-2025-23366","body":"## Overview\n\nA flaw was found in the HAL Console in the Wildfly component, which does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a web page that is served to other users. The attacker must be authenticated as a user that belongs to management groups “SuperUser”, “Admin”, or “Maintainer”.\n\n## Affected\n\n- `hal_management_console < 3.7.7`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `hal_management_console 3.7.7`\n\n## Vendor advisories\n\n- **RHSA-2025:10931** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform 7 · released 2025-07-14 · [advisory](https://access.redhat.com/errata/RHSA-2025:10931)\n- **Red Hat VEX** · Moderate · affected: Red Hat JBoss Data Grid 7, Red Hat JBoss Enterprise Application Platform 8 · no fix planned: Red Hat JBoss Data Grid 7, Red Hat JBoss Enterprise Application Platform 8 · updated 2026-09-12 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-23366.json)","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}