CVE-2025-0668: BOINC Server Multiple SQL Injections
Published May 7, 2025
·Updated
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Server allows Stored XSS.This issue affects BOINC Server: before 1.4.5.
Affected Software
2 affected components
BOINC BOINC Server<1.4.5
Universityofcalifornia Boinc Server<1.4.5
Event History
May 7, 2025
CVE Published
via MITRE·07:39 AM
Data Sourced
via MITRE·07:39 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-0668?
CVE-2025-0668 has a medium severity rating due to its potential for stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2025-0668?
To fix CVE-2025-0668, upgrade to BOINC Server version 1.4.5 or later.
3
What software does CVE-2025-0668 affect?
CVE-2025-0668 affects BOINC Server versions prior to 1.4.5.
4
What kind of vulnerability is CVE-2025-0668?
CVE-2025-0668 is an improper neutralization of input during web page generation, specifically a stored XSS vulnerability.
5
Can CVE-2025-0668 be exploited remotely?
Yes, CVE-2025-0668 can be exploited remotely by attackers via malicious input that is stored on the server.