216.73.216.197

CVE-2025-67634

· Published 12/12/2025 21:15 · Modified 15/12/2025 18:22

Labels: CVE-2025-67634 2025-12-129119a7d8-5eab-497f-8521-727c672e3725CVE-2025-67634

Essential information

Published
12/12/2025 21:15
Modified
15/12/2025 18:22
Author
Creator
CVSS
4.6 MEDIUM (v3) 4.6 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

The CISA Software Acquisition Guide Supplier Response Web Tool before 2025-12-11 was vulnerable to cross-site scripting via text fields. If an attacker could convince a user to import a specially-crafted JSON file, the Tool would load JavaScript from the file into the page. The JavaScript would execute in the context of the user's browser when the user submits the page (clicks 'Next').

NVD status

Status
Undergoing Analysis — CVE is currently being analyzed by NVD staff, this process results in association of reference link tags, CVSS scores, CWE association, and CPE applicability statements.
Source
9119a7d8-5eab-497f-8521-727c672e3725
NVD
View on NVD

References