Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Server allows Stored XSS.This issue affects BOINC Server: before 1.4.5.
References
Link | Resource |
---|---|
https://www.compass-security.com/fileadmin/Research/Advisories/2025_03_CSNC-2025-004_BOINC_multiple_SQLi.txt | Third Party Advisory Exploit |
https://www.compass-security.com/fileadmin/Research/Advisories/2025_03_CSNC-2025-004_BOINC_multiple_SQLi.txt | Third Party Advisory Exploit |
Configurations
History
08 Jul 2025, 16:47
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-07 08:15
Updated : 2025-07-08 16:47
NVD link : CVE-2025-0668
Mitre link : CVE-2025-0668
CVE.ORG link : CVE-2025-0668
JSON object : View
Products Affected
universityofcalifornia
- boinc_server
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')