AVEVA PI Web API Cross-site Scripting
Vulnerability Description
A cross-site scripting vulnerability exists in AVEVA PI Web API version 2023 SP1 and prior that, if exploited, could allow an authenticated attacker (with privileges to create/update annotations or upload media files) to persist arbitrary JavaScript code that will be executed by users who were socially engineered to disable content security policy protections while rendering annotation attachments from within a web browser.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-2745
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- AVEVA reported this vulnerability to CISA.
References
More from AVEVA
View All →Affected Vendor
AVEVA
View all reports →