Stored XSS in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker to obtain limited information from other user sessions. User interaction is required.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Stored XSS in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker to obtain limited information from other user sessions. User interaction is required.
How easy to exploit
Severity of consequences
Likelihood of exploitation in next 30 days