CVE-2025-5015: Parsons Aclaraone Utility Portal

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A cross-site scripting vulnerability exists in the AccuWeather and Custom RSS widget that allows an unauthenticated user to replace the RSS feed URL with a malicious one.

Affected products

  • Parsons Aclaraone Utility Portal: before 1.22 (fixed in 1.22)
  • Parsons Parsons Utility Enterprise Data Management: version 5.18 only; version 5.03 only; from 4.02, up to and including 4.26; version 3.30 only

Published 2025-06-25. Last modified 2026-06-17.