PT-2025-26599 · Jetbrains · Teamcity

CVE-2025-52876

·

Published

2025-06-23

·

Updated

2026-08-24

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions JetBrains TeamCity versions prior to 2025.03.3
Description JetBrains TeamCity is affected by a reflected Cross-Site Scripting (XSS) issue on the favoriteIcon page. This occurs because the application fails to properly protect the web page structure, allowing a remote attacker to execute malicious scripts in the context of a user's session.
Recommendations Update to version 2025.03.3.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-07634
CVE-2025-52876

Affected Products

Teamcity