← Volver a CVEs
CVE-2025-63442
MEDIUM4.6
Descripcion
Simple User Management System with PHP-MySQL v1.0 is vulnerable to Cross-Site Scripting (XSS) via the Profile Section. The system fails to properly sanitize user input, allowing attackers to inject and execute arbitrary JavaScript when the input is displayed in the browser
Detalles CVE
Puntuacion CVSS v3.14.6
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioREQUIRED
Publicado11/3/2025
Ultima modificacion11/5/2025
Fuentenvd
Avistamientos honeypot0
Productos afectados
nababur:simple-user-management-system
Debilidades (CWE)
CWE-79
Referencias
https://github.com/sanin-s1r3n/CVE-Research/blob/main/CVE-5(cve@mitre.org)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.