- Description
- Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is processed during the website�s page generation, resulting in the creation of malicious content. When this malicious content gets executed, the attacker could gain the ability to access/modify information within the scope of victim�s browser.
- Source
- cna@sap.com
- NVD status
- Deferred
CVSS 3.1
- Type
- Secondary
- Base score
- 6.1
- Impact score
- 2.7
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
- cna@sap.com
- CWE-79
- Hype score
- Not currently trending
CVE-2025-42948 Cross-Site Scripting Vulnerability in SAP NetWeaver ABAP Platform Enables Unauthorized Access https://t.co/nH2xkNdjQ3
@VulmonFeeds
12 Aug 2025
94 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-42948 Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly acc… https://t.co/mpGjIb7Wbx
@CVEnew
12 Aug 2025
245 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes