CVE-2025-52218

7.5

SelectZero · Data Observability Platform

SelectZero Data Observability Platform before 2025.5.2 is vulnerable to content spoofing and text injection due to improper input sanitization on the login page.

Executive summary

A content spoofing and text injection vulnerability in the SelectZero Data Observability Platform allows unauthenticated attackers to manipulate the login page interface.

Vulnerability

This is a content spoofing and text injection vulnerability caused by improper sanitization of unspecified parameters. An unauthenticated attacker can inject arbitrary text or limited HTML into the application login page.

Business impact

The vulnerability carries a CVSS score of 7.5, reflecting a significant risk to the integrity of the user interface. Attackers can leverage this flaw to conduct phishing campaigns or social engineering attacks by presenting fraudulent information on a trusted login portal, which may lead to credential theft and organizational reputational damage.

Remediation

Immediate Action: Update the SelectZero Data Observability Platform to version 2025.5.2 or later as specified in the official vendor change log.

Proactive Monitoring: Audit web server and application access logs for unusual patterns involving unexpected characters or scripts injected into login-related URL parameters.

Compensating Controls: Deploy a Web Application Firewall (WAF) with configured rules to detect and block malicious HTML or script tags within incoming HTTP requests targeting the authentication endpoint.

Exploitation status

Public Exploit Available: No — there is no evidence of a public exploit for this vulnerability.

Analyst recommendation

Given the potential for this vulnerability to facilitate credential harvesting through deceptive login pages, organizations should prioritize the update to version 2025.5.2. Failure to remediate could expose users to sophisticated phishing attempts that bypass standard security awareness indicators due to the legitimacy of the host platform.

Sources