CVE-2025-10573: Ivanti EPM Unauthenticated Stored Cross-Site Scripting (Fixed)

TL;DR


Summary:
- This article discusses a security vulnerability (CVE-2025-10573) found in the Ivanti Endpoint Manager (EPM) software.
- The vulnerability allowed attackers to perform unauthenticated, stored cross-site scripting (XSS) attacks, which could allow them to execute malicious scripts on the affected systems.
- Ivanti has released a patch to fix this vulnerability, and the article encourages users to update their Ivanti EPM software to the latest version to protect against this security issue.

Like summarized versions? Support us on Patreon!