CVE-2025-2124 describes a problematic cross-site scripting (XSS) vulnerability in Control iD RH iD version 25.2.25.0, specifically within the API Handler component's /v2/customerdb/person.svc/change_password file when handling the 'message' argument. This vulnerability carries a low CVSS score of 3.5, indicating a low impact on integrity and no impact on confidentiality or availability, with an attack vector that can be exploited remotely with low attack complexity. While the exploit has been publicly disclosed, there is currently no evidence of active exploitation, no readily available exploit intelligence in common frameworks, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Control ID | RH ID | 25.2.25.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.