CVE-2025-0667: BOINC Server Stored XSS Injection in pm.php
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Server allows Stored XSS.This issue affects BOINC Server: through 1.4.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0667?
CVE-2025-0667 is classified as a high severity vulnerability due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2025-0667?
To fix CVE-2025-0667, upgrade BOINC Server to a version later than 1.4.7 that addresses this XSS vulnerability.
What causes CVE-2025-0667?
CVE-2025-0667 is caused by improper neutralization of input during web page generation, allowing attackers to inject malicious scripts.
What are the potential impacts of CVE-2025-0667?
The impacts of CVE-2025-0667 include unauthorized access to user data and the ability to execute malicious scripts in the context of the user's browser.
In which versions of BOINC Server is CVE-2025-0667 present?
CVE-2025-0667 is present in BOINC Server versions up to and including 1.4.7.