CVE-2025-22491 MEDIUM

CVE-2025-22491: Improper Input Validation in Foreseer Reporting Software (FRS)

Vendor Eaton
Product Foreseer Reporting Software (FRS)
Weakness CWE-79 · XSS
Published February 28, 2025
Last update August 26, 2025

CVSS base score

6.7/10
Attack vector Local
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

The user input was not sanitized on Reporting Hierarchy Management page of Foreseer Reporting Software (FRS) application which could lead into execution of arbitrary JavaScript in a browser context for all the interacting users. This security issue has been patched in the latest version 1.5.100 of the FRS.

Key dates

02Disclosure timeline

February 28, 2025 CVE published
August 26, 2025 Record updated