← Retour aux CVEs
CVE-2025-15188
LOW2.4
Description
A vulnerability was determined in Campcodes Complete Online Beauty Parlor Management System 1.0. This vulnerability affects unknown code of the file /admin/search-invoices.php. Executing a manipulation of the argument searchdata can lead to cross site scripting. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Details CVE
Score CVSS v3.12.4
SeveriteLOW
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisHIGH
Interaction utilisateurREQUIRED
Publie12/29/2025
Derniere modification4/29/2026
Sourcenvd
Observations honeypot0
Produits affectes
campcodes:online_beauty_parlor_management_system
Faiblesses (CWE)
CWE-79CWE-94CWE-79
References
https://github.com/BUPT2025201/CVE/issues/1(cna@vuldb.com)
https://vuldb.com/?ctiid.338573(cna@vuldb.com)
https://vuldb.com/?id.338573(cna@vuldb.com)
https://vuldb.com/?submit.721868(cna@vuldb.com)
https://www.campcodes.com/(cna@vuldb.com)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.