CVE-2025-8319: XSS
Published Jul 29, 2025
·Updated
the BMA login interface allows arbitrary JavaScript or HTML to be written straight into the page’s Document Object Model via the error= URL parameter
Affected Software
1 affected component
Barracuda Message Archiver Firmware=5.4.2.002
Event History
Jul 29, 2025
CVE Published
via MITRE·11:31 PM
Data Sourced
via MITRE·11:31 PM
DescriptionWeakness
Jul 30, 2025
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Mar 31, 57633
Event
via FIRST·09:27 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-8319?
CVE-2025-8319 is classified with a high severity due to its potential for arbitrary code execution through XSS.
2
How do I fix CVE-2025-8319?
To fix CVE-2025-8319, update Barracuda Message Archiver Firmware to version 5.4.2.003 or later.
3
What systems are affected by CVE-2025-8319?
CVE-2025-8319 affects Barracuda Message Archiver Firmware version 5.4.2.002.
4
What type of attack can be performed using CVE-2025-8319?
CVE-2025-8319 can be exploited to perform a cross-site scripting (XSS) attack, allowing injection of arbitrary JavaScript or HTML.
5
Is authentication required to exploit CVE-2025-8319?
No, CVE-2025-8319 can be exploited without authentication, making it more dangerous.