CVE-2025-2745 - CVE House
Back to Database
Status published Medium CVE-2025-2745

AVEVA PI Web API Cross-site Scripting

Vulnerability Description

A cross-site scripting vulnerability exists in AVEVA PI Web API version 2023 SP1 and prior that, if exploited, could allow an authenticated attacker (with privileges to create/update annotations or upload media files) to persist arbitrary JavaScript code that will be executed by users who were socially engineered to disable content security policy protections while rendering annotation attachments from within a web browser.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-2745

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • AVEVA reported this vulnerability to CISA.

Affected Vendor

Affected Software

PI Web API
Vulnerable Versions:
0

Timeline

Official Publish: June 12th, 2025
Last Modified: June 12th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:N

Weaknesses (CWE)