CVE-2025-8319 Details
Description
the BMA login interface allows arbitrary JavaScript or HTML to be written straight into the page’s Document Object Model via the error= URL parameter
A DOM-based cross-site scripting vulnerability has been identified in Barracuda Message Archiver (BMA) version 5.4.2.002. The issue arises in the login interface, where the 'error=' URL parameter is not properly sanitized before being injected into the Document Object Model (DOM). This flaw allows attackers to execute arbitrary JavaScript or HTML in the victim's browser. Exploitation of this vulnerability could lead to serious consequences, such as session hijacking, credential theft, and unauthorized execution of actions on behalf of the user.
Barracuda should sanitize and encode all data from URL parameters before it reaches the DOM. Users can temporarily strip or encode the 'error' parameter using a reverse proxy or web application firewall until a patch is available.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://bugcrowd.com/disclosures/30a330ef-0885-458c-a64f-2ad63d196b4d/dom-based-cross-site-scripting-xss-with-keylogger-injection-via-the-error-parameter-in-barracuda-mail-archiver | CISA-ADP | ExploitIssue TrackingMitigationThird Party Advisory |
| https://bugcrowd.com/disclosures/30a330ef-0885-458c-a64f-2ad63d196b4d/dom-based-cross-site-scripting-xss-with-keylogger-injection-via-the-error-parameter-in-barracuda-mail-archiver | Bugcrowd Inc. | ExploitIssue TrackingMitigationThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| barracuda message archiver firmware | 5.4.2.002 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Bugcrowd Inc. |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2025 | Initial Analysis | [email protected] |
| Jul 30, 2025 | CVE Modified | CISA-ADP |
| Jul 30, 2025 | New CVE Received | Bugcrowd Inc. |