CVE-2025-2745 MEDIUM

CVE-2025-2745: AVEVA PI Web API Cross-site Scripting

Vendor Aveva
Product PI Web API
Weakness CWE-79 · XSS
Published June 12, 2025
Last update June 12, 2025

CVSS base score

6.5/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction Required
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:N

What the vulnerability does

01Description

A cross-site scripting vulnerability exists in AVEVA PI Web API version 2023 SP1 and prior that, if exploited, could allow an authenticated attacker (with privileges to create/update annotations or upload media files) to persist arbitrary JavaScript code that will be executed by users who were socially engineered to disable content security policy protections while rendering annotation attachments from within a web browser.

Key dates

02Disclosure timeline

June 12, 2025 CVE published
June 12, 2025 Record updated