CVE-2025-64392
Received Received - Intake

Reflected Cross-Site Scripting in Veeam Backup Enterprise Manager

Vulnerability report for CVE-2025-64392, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: HackerOne

Description

This vulnerability in Veeam Backup Enterprise Manager allows an attacker to execute script in the browser of a portal user who opens a crafted link.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Veeam Backup Enterprise Manager 12

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a reflected cross-site scripting (XSS) vulnerability in Veeam Backup Enterprise Manager. An attacker can trick an authenticated user into clicking a malicious link, which executes a script in the user's browser. The vulnerability exists in versions 12.3.2.4854 and earlier within the 12.x series.

Detection Guidance

To detect this vulnerability, check the version of Veeam Backup Enterprise Manager running on your system. Compare it against version 12.3.2.4854 or earlier. If the version is 12.3.2.4934 or higher, the system is not vulnerable. Additionally, monitor network traffic for suspicious links or unusual script execution in the browser.

Impact Analysis

An attacker could steal session cookies, perform actions on behalf of the user, or redirect the user to malicious websites. This could lead to unauthorized access to sensitive data or account takeover if the user has elevated privileges.

Compliance Impact

This vulnerability could lead to unauthorized data access or disclosure, violating GDPR's data protection principles or HIPAA's security requirements. Organizations may face compliance violations, fines, or reputational damage if exploited.

Mitigation Strategies

Immediately update Veeam Backup & Replication to version 12.3.2 P4 (build 12.3.2.4934) or later. This patched version resolves the vulnerability. Ensure all users are aware of the risk of clicking untrusted links until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-64392. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart