First published: Wed May 07 2025(Updated: )
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Server allows Stored XSS.This issue affects BOINC Server: through 1.4.7.
Credit: vulnerability@ncsc.ch
Affected Software | Affected Version | How to fix |
---|---|---|
BOINC BOINC Server | <=1.4.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0666 has a medium severity rating due to its potential for stored Cross-site Scripting (XSS) attacks.
To fix CVE-2025-0666, upgrade the BOINC Server to version 1.4.8 or later to eliminate the vulnerability.
The risks include unauthorized script execution in user browsers, which can lead to data theft or session hijacking.
CVE-2025-0666 affects all versions of BOINC Server up to and including 1.4.7.
Users may fall victim to malicious scripts that can steal sensitive data or manipulate their web experience.