CVE-2025-0057

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Jan 14, 2025
CWE ID 434

Summary

CVE-2025-0057 is a stored cross-site scripting (XSS) vulnerability affecting SAP NetWeaver AS Java's User Admin Application. An attacker, impersonating an admin, can exploit this flaw by uploading a maliciously crafted image file containing JavaScript code. When an unsuspecting user visits the vulnerable component, the attacker gains the ability to read and manipulate information within the victim's web browser, potentially leading to data theft or unauthorized actions.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share