Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Medium

Stored XSS in Ivanti Endpoint Manager incomingdata API

IdentifiersCVE-2025-10573CWE-79· Improper Neutralization of Input…

CVE-2025-10573 is a critical stored cross-site scripting vulnerability in Ivanti Endpoint Manager (EPM) affecting versions prior to 2024 SU4 SR1. The flaw is in the incomingdata web API and associated CGI handler, postcgi.exe, which processes device scan data submitted in key=value format. An unauthenticated attacker can submit crafted fake managed-endpoint scan data containing malicious JavaScript. That data is subsequently embedded in the EPM administrative web dashboard without proper sanitization or output encoding. When an administrator views the poisoned dashboard, the attacker-controlled script executes in the context of the administrator’s browser session. This enables session hijacking and can turn a client-side XSS condition into effective administrative compromise of the EPM environment.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an unauthenticated remote attacker to execute arbitrary JavaScript in the context of an EPM administrator session, hijack that session, and perform actions available to the administrator. Given EPM’s role as an endpoint management platform, this can enable broad administrative control over managed devices, including remote management actions, software deployment, configuration changes, and potentially follow-on code execution across enterprise endpoints. The vulnerability therefore creates a path from unauthenticated input to privileged administrative compromise and large-scale downstream impact.

Mitigation

If you can’t patch tonight, do this now.

Until patching is completed, restrict EPM access so it is not internet-facing, limit the EPM web service and management interfaces to trusted subnets or administrative networks, and apply network segmentation around the EPM server. Monitor scan-ingestion and incomingdata activity for suspicious device scan submissions or JavaScript-like payloads, review dashboard content and administrator session activity for signs of session theft or unauthorized actions, and treat untrusted or newly registered endpoints as suspicious. These measures reduce exposure but do not replace vendor patching.

Remediation

Patch, then assume compromise.

Upgrade Ivanti Endpoint Manager to 2024 SU4 SR1 or later. Ivanti states that EPM 2024 SU4 SR1 fixes CVE-2025-10573. Organizations running unsupported branches should migrate to a supported fixed release, as unsupported versions may not receive security updates.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
IvantiEndpoint Managerapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

ACTIVITY FEED

Recent activity

46 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity32

Community discussion across Reddit, Mastodon, and other social sources.

Stored XSS in Ivanti Endpoint Manager incomingdata API (CVE-2025-10573) | Mallory