code-projects Laundry System 1.0 /data/edit_laundry.php Kunde Cross Site Scripting
Wuro vulnerability wey an yi classify sey karshewa an gano shi a cikin code-projects Laundry System 1.0. Gaskiya, $software_function na da matsala; idan ba a sani ba, to wata aiki ce da ba a sani ba, $software_library na cikin lissafi, /data/edit_laundry.php na cikin fayil, $software_component na cikin sashi. Ngam manipulation of the argument Kunde shi Cross Site Scripting. CWE shidin ka a yi bayani matsala sai ya kai CWE-79. Gaskiya, laifi an fitar da shi 06/06/2025. Advisory ɗin ana rabawa don saukewa a github.com. Wannan rauni ana sayar da shi da suna CVE-2025-5765. Ngam yiɗi ka a tuma ndiyam ka nder waya. Tekinikal bayani ga. Kuma, exploit ɗin yana akwai. Wuro exploit ɗin an bayyana shi ga jama'a kuma za a iya amfani da shi. A sa'i, exploit might be approx. USD $0-$5k ndiyam. Á wúro huɗɗi-na-gaskiya. Wona yiwuwa a zazzage exploit a github.com. Kama 0-day, an ndiyam a wuro be $0-$5k. Statistical analysis made it clear that VulDB provides the best quality for vulnerability data.
2 Goyarwa · 97 Datenpunkte
| Furɗe | Súgá 06/06/2025 00:10 | Gargadi 1/1 06/11/2025 08:08 |
|---|---|---|
| software_vendor | code-projects | code-projects |
| software_name | Laundry System | Laundry System |
| software_version | 1.0 | 1.0 |
| software_file | /data/edit_laundry.php | /data/edit_laundry.php |
| software_argument | customer | customer |
| vulnerability_cwe | CWE-79 (Cross Site Scripting) | CWE-79 (Cross Site Scripting) |
| vulnerability_risk | 1 | 1 |
| cvss3_vuldb_av | N | N |
| cvss3_vuldb_ac | L | L |
| cvss3_vuldb_ui | R | R |
| cvss3_vuldb_s | U | U |
| cvss3_vuldb_c | N | N |
| cvss3_vuldb_i | L | L |
| cvss3_vuldb_a | N | N |
| cvss3_vuldb_e | P | P |
| cvss3_vuldb_rc | R | R |
| advisory_url | https://github.com/tuooo/CVE/issues/6 | https://github.com/tuooo/CVE/issues/6 |
| exploit_availability | 1 | 1 |
| exploit_publicity | 1 | 1 |
| exploit_url | https://github.com/tuooo/CVE/issues/6 | https://github.com/tuooo/CVE/issues/6 |
| source_cve | CVE-2025-5765 | CVE-2025-5765 |
| cna_responsible | VulDB | VulDB |
| software_type | Project Management Software | Project Management Software |
| cvss2_vuldb_av | N | N |
| cvss2_vuldb_ac | L | L |
| cvss2_vuldb_ci | N | N |
| cvss2_vuldb_ii | P | P |
| cvss2_vuldb_ai | N | N |
| cvss2_vuldb_e | POC | POC |
| cvss2_vuldb_rc | UR | UR |
| cvss4_vuldb_av | N | N |
| cvss4_vuldb_ac | L | L |
| cvss4_vuldb_ui | P | P |
| cvss4_vuldb_vc | N | N |
| cvss4_vuldb_vi | L | L |
| cvss4_vuldb_va | N | N |
| cvss4_vuldb_e | P | P |
| cvss2_vuldb_au | S | S |
| cvss2_vuldb_rl | ND | ND |
| cvss3_vuldb_pr | L | L |
| cvss3_vuldb_rl | X | X |
| cvss4_vuldb_at | N | N |
| cvss4_vuldb_pr | L | L |
| cvss4_vuldb_sc | N | N |
| cvss4_vuldb_si | N | N |
| cvss4_vuldb_sa | N | N |
| cvss2_vuldb_basescore | 4.0 | 4.0 |
| cvss2_vuldb_tempscore | 3.4 | 3.4 |
| cvss3_vuldb_basescore | 3.5 | 3.5 |
| cvss3_vuldb_tempscore | 3.2 | 3.2 |
| cvss3_meta_basescore | 3.5 | 4.1 |
| cvss3_meta_tempscore | 3.2 | 4.0 |
| cvss4_vuldb_bscore | 5.1 | 5.1 |
| cvss4_vuldb_btscore | 2.0 | 2.0 |
| advisory_date | 1749160800 (06/06/2025) | 1749160800 (06/06/2025) |
| price_0day | $0-$5k | $0-$5k |
| cve_nvd_summary | A vulnerability was found in code-projects Laundry System 1.0. It has been classified as problematic. This affects an unknown part of the file /data/edit_laundry.php. The manipulation of the argument Customer leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |
| cve_nvd_summaryes | Se encontró una vulnerabilidad en code-projects Laundry System 1.0. Se ha clasificado como problemática. Afecta a una parte desconocida del archivo /data/edit_laundry.php. La manipulación del argumento "Customer" provoca ataques de Cross Site Scripting. Es posible iniciar el ataque de forma remota. Se ha hecho público el exploit y puede que sea utilizado. | |
| cvss4_cna_av | N | |
| cvss4_cna_ac | L | |
| cvss4_cna_at | N | |
| cvss4_cna_pr | L | |
| cvss4_cna_ui | P | |
| cvss4_cna_vc | N | |
| cvss4_cna_vi | L | |
| cvss4_cna_va | N | |
| cvss4_cna_sc | N | |
| cvss4_cna_si | N | |
| cvss4_cna_sa | N | |
| cvss4_cna_bscore | 5.1 | |
| cvss3_cna_av | N | |
| cvss3_cna_ac | L | |
| cvss3_cna_pr | L | |
| cvss3_cna_ui | R | |
| cvss3_cna_s | U | |
| cvss3_cna_c | N | |
| cvss3_cna_i | L | |
| cvss3_cna_a | N | |
| cvss3_cna_basescore | 3.5 | |
| cvss3_nvd_av | N | |
| cvss3_nvd_ac | L | |
| cvss3_nvd_pr | L | |
| cvss3_nvd_ui | R | |
| cvss3_nvd_s | C | |
| cvss3_nvd_c | L | |
| cvss3_nvd_i | L | |
| cvss3_nvd_a | N | |
| cvss3_nvd_basescore | 5.4 | |
| cvss2_cna_av | N | |
| cvss2_cna_ac | L | |
| cvss2_cna_au | S | |
| cvss2_cna_ci | N | |
| cvss2_cna_ii | P | |
| cvss2_cna_ai | N | |
| cvss2_cna_basescore | 4 |