CVE-2025-40900Disclosure(nozominetworks / cmc)

LOWCVSS 5.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report containing an Angular template payload, or a victim can be socially engineered to import a malicious report template. When the victim views or imports the report, the Angular template executes in their browser context, allowing the attacker to modify application data, or disrupt application availability. Full XSS exploitation and direct information disclosure are prevented by the existing input validation and Content Security Policy configuration.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1336

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cmc
  • guardian

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
cmcguardian

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-19: 1Technical Details · 2026-05-19: 105-19
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CVE@CVEnew
    Disclosure

    CVE-2025-40900 An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with r… https://www.cve.org/CVERecord?id=CVE-2025-40900

    Post summary

    A brief disclosure of CVE‑2025‑40900, describing it as an Angular template injection flaw in the Reports feature caused by improper validation, with no mention of PoC, exploitation, patches, or false‑positive status.

    000001.0K
    57.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appnozominetworkscmc---
Appnozominetworksguardian---

Explore more