First published: Wed May 07 2025(Updated: )
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Server allows Stored XSS.This issue affects BOINC Server: through 1.4.7.
Credit: vulnerability@ncsc.ch
Affected Software | Affected Version | How to fix |
---|---|---|
BOINC BOINC Server | <=1.4.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0667 is classified as a high severity vulnerability due to its potential for stored cross-site scripting attacks.
To fix CVE-2025-0667, upgrade BOINC Server to a version later than 1.4.7 that addresses this XSS vulnerability.
CVE-2025-0667 is caused by improper neutralization of input during web page generation, allowing attackers to inject malicious scripts.
The impacts of CVE-2025-0667 include unauthorized access to user data and the ability to execute malicious scripts in the context of the user's browser.
CVE-2025-0667 is present in BOINC Server versions up to and including 1.4.7.