CVE-2025-26653

SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an attacker, without requiring any privileges, to inject malicious JavaScript into a website. When a user visits the compromised page, the injected script gets executed, potentially compromising the confidentiality and integrity within the scope of the victim?s browser. Availability is not impacted.
Configurations

No configuration.

History

08 Apr 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-08 08:15

Updated : 2025-04-08 08:15


NVD link : CVE-2025-26653

Mitre link : CVE-2025-26653


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')