CVE-2025-25242
published 2025-03-11CVE-2025-25242: SAP NetWeaver Application Server ABAP allows malicious scripts to be executed in the application, potentially leading to a Cross-Site Scripting (XSS)…
PriorityP425medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.24%
15.4th percentile
SAP NetWeaver Application Server ABAP allows malicious scripts to be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application, but it can have some minor impact on its confidentiality and integrity.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gogs.io | gogs | >= 0 < 0.14.1 | 0.14.1 |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Unauthenticated File Upload in Gogs
ghsa·2026-02-17
CVE-2026-25242 [MEDIUM] CWE-862 Unauthenticated File Upload in Gogs
Unauthenticated File Upload in Gogs
Security Advisory:Unauthenticated File Upload in Gogs
Vulnerability Type: Unauthenticated File Upload
Date: Aug 5, 2025
Discoverer: OpenAI Security Research
## Summary
Gogs exposes unauthenticated file upload endpoints by default. When the global RequireSigninView setting is disabled (default), any remote user can upload arbitrary files to the server via /releases/attachments and /issues/attachments. This enables the instance to be abused as a public file host, potentially leading to disk exhaustion, content hosting, or delivery of malware. CSRF tokens do not mitigate this attack due to same-origin cookie issuance.
## Affected Versions
- Software: [Gogs](https://github.com/gogs/gogs/tree/main)
- Confirmed Version(s): 28f83626d4ed0aa7b89493be2ea8b79ca
GHSA
GHSA-chhf-863p-8gx2: SAP NetWeaver Application Server ABAP allows malicious scripts to be executed in the application, potentially leading to a Cross-Site Scripting (XSS)
ghsa_unreviewed·2025-03-11
CVE-2025-25242 [MEDIUM] CWE-79 GHSA-chhf-863p-8gx2: SAP NetWeaver Application Server ABAP allows malicious scripts to be executed in the application, potentially leading to a Cross-Site Scripting (XSS)
SAP NetWeaver Application Server ABAP allows malicious scripts to be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application, but it can have some minor impact on its confidentiality and integrity.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-03-11
Published