CVE-2025-24867
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Feb 11, 2025
CWE ID 79
Summary
CVE-2025-24867 is a Cross-Site Scripting (XSS) vulnerability affecting the SAP BusinessObjects Platform BI Launchpad. This issue arises due to insufficient input handling, allowing an unauthenticated attacker to embed malicious scripts into unprotected parameters. By crafting a specially crafted URL, an attacker can execute the script in a victim's browser, potentially gaining access to and modifying sensitive information related to the web client without disrupting availability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share