CVE-2025-0666: BOINC Server Stored XSS Injection in host_venue_action.php
Published May 7, 2025
·Updated
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Server allows Stored XSS.This issue affects BOINC Server: through 1.4.7.
Affected Software
2 affected components
BOINC BOINC Server<=1.4.7
Universityofcalifornia Boinc Server<=1.4.7
Event History
May 7, 2025
CVE Published
via MITRE·07:38 AM
Data Sourced
via MITRE·07:38 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-0666?
CVE-2025-0666 has a medium severity rating due to its potential for stored Cross-site Scripting (XSS) attacks.
2
How do I fix CVE-2025-0666?
To fix CVE-2025-0666, upgrade the BOINC Server to version 1.4.8 or later to eliminate the vulnerability.
3
What are the risks associated with CVE-2025-0666?
The risks include unauthorized script execution in user browsers, which can lead to data theft or session hijacking.
4
Which versions of BOINC Server are affected by CVE-2025-0666?
CVE-2025-0666 affects all versions of BOINC Server up to and including 1.4.7.
5
How can CVE-2025-0666 impact users?
Users may fall victim to malicious scripts that can steal sensitive data or manipulate their web experience.