cve/2025/CVE-2025-42948.md
2025-09-29 21:09:30 +02:00

1.8 KiB
Raw Blame History

CVE-2025-42948

Description

Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is processed during the website<74>s page generation, resulting in the creation of malicious content. When this malicious content gets executed, the attacker could gain the ability to access/modify information within the scope of victim<69>s browser.

POC

Reference

No PoCs from references.

Github