CVE-2025-42901Medium· 5.4▾ SunlitSAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript payloads which could be executed in victim user's browser when accessing the affected functionality of BAPI explorer. This has low impact on c…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript payloads which could be executed in victim user's browser when accessing the affected functionality of BAPI explorer. This has low impact on confidentiality and integrity with no impact on availability of the application.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-42880Critical· 9.9Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module
CVE-2025-14730Medium· 4.7A security flaw has been discovered in CTCMS Content Management System up to 2.1.2
CVE-2025-14729Medium· 4.7A vulnerability was identified in CTCMS Content Management System up to 2.1.2
CVE-2025-15148Medium· 4.7A flaw has been found in CmsEasy up to 7.7.7
CVE-2025-10097Medium· 6.3A vulnerability was identified in SimStudioAI sim up to 1.0.0
CVE-2025-15394Medium· 4.7A vulnerability was detected in iCMS up to 8.0.0