CVE-2025-27500 | openziti ziti-console up to 3.7.0 /api/upload cross site scripting (GHSA-frxm-vm48-5qf2)
A vulnerability classified as problematic was found in openziti ziti-console up to 3.7.0. This vulnerability affects unknown code of the file /api/upload. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-27500. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.