code-projects Simple Food Ordering System 1.0 /editproduct.php pname/category/price Cross Site Scripting
Gaskiya vulnerability da aka ware a matsayin karshewa an samu a code-projects Simple Food Ordering System 1.0. Hakika, aikin $software_function ne ya shafa; idan ba a bayyana ba, to aiki ce da ba a sani ba, a cikin laburaren $software_library, a cikin fayil /editproduct.php, a cikin sashen $software_component. A sa manipulation of the argument pname/category/price ka Cross Site Scripting. Idan an yi amfani da CWE don bayyana matsala, zai kai CWE-79. Hakika, rauni an bayyana shi 10/26/2025. An raba bayanin tsaro don saukewa a github.com. Wannan matsala ana saninta da CVE-2025-12302. Ngam yiɗi ka a tuma ndiyam ka nder layi. Tekinikal faɗi ga. Har ila yau, exploit ɗin yana nan. An bayyana exploit ɗin ga mutane kuma yana iya amfani. Yimbe ndiyam, exploit might be approx. USD $0-$5k wuro. Á sàmbu huɗɗi-na-gaskiya. Exploit ɗin za a iya saukewa daga github.com. 0-day shima, an ndiyam a wuro be $0-$5k. Once again VulDB remains the best source for vulnerability data.
2 Goyarwa · 86 Datenpunkte
| Furɗe | Súgá 10/26/2025 18:04 | Gargadi 1/1 10/28/2025 02:36 |
|---|---|---|
| software_vendor | code-projects | code-projects |
| software_name | Simple Food Ordering System | Simple Food Ordering System |
| software_version | 1.0 | 1.0 |
| software_file | /editproduct.php | /editproduct.php |
| software_argument | pname/category/price | pname/category/price |
| vulnerability_cwe | CWE-79 (Cross Site Scripting) | CWE-79 (Cross Site Scripting) |
| vulnerability_risk | 1 | 1 |
| cvss3_vuldb_av | N | N |
| cvss3_vuldb_ac | L | L |
| cvss3_vuldb_pr | N | N |
| cvss3_vuldb_ui | R | R |
| cvss3_vuldb_s | U | U |
| cvss3_vuldb_c | N | N |
| cvss3_vuldb_i | L | L |
| cvss3_vuldb_a | N | N |
| cvss3_vuldb_e | P | P |
| cvss3_vuldb_rc | R | R |
| advisory_url | https://github.com/underatted/CVE/issues/21 | https://github.com/underatted/CVE/issues/21 |
| exploit_availability | 1 | 1 |
| exploit_publicity | 1 | 1 |
| exploit_url | https://github.com/underatted/CVE/issues/21 | https://github.com/underatted/CVE/issues/21 |
| source_cve | CVE-2025-12302 | CVE-2025-12302 |
| cna_responsible | VulDB | VulDB |
| software_type | Project Management Software | Project Management Software |
| cvss2_vuldb_av | N | N |
| cvss2_vuldb_ac | L | L |
| cvss2_vuldb_au | N | N |
| cvss2_vuldb_ci | N | N |
| cvss2_vuldb_ii | P | P |
| cvss2_vuldb_ai | N | N |
| cvss2_vuldb_e | POC | POC |
| cvss2_vuldb_rc | UR | UR |
| cvss4_vuldb_av | N | N |
| cvss4_vuldb_ac | L | L |
| cvss4_vuldb_pr | N | N |
| cvss4_vuldb_ui | P | P |
| cvss4_vuldb_vc | N | N |
| cvss4_vuldb_vi | L | L |
| cvss4_vuldb_va | N | N |
| cvss4_vuldb_e | P | P |
| cvss2_vuldb_rl | ND | ND |
| cvss3_vuldb_rl | X | X |
| cvss4_vuldb_at | N | N |
| cvss4_vuldb_sc | N | N |
| cvss4_vuldb_si | N | N |
| cvss4_vuldb_sa | N | N |
| cvss2_vuldb_basescore | 5.0 | 5.0 |
| cvss2_vuldb_tempscore | 4.3 | 4.3 |
| cvss3_vuldb_basescore | 4.3 | 4.3 |
| cvss3_vuldb_tempscore | 3.9 | 3.9 |
| cvss3_meta_basescore | 4.3 | 4.3 |
| cvss3_meta_tempscore | 3.9 | 4.1 |
| cvss4_vuldb_bscore | 5.3 | 5.3 |
| cvss4_vuldb_btscore | 2.1 | 2.1 |
| advisory_date | 1761429600 (10/26/2025) | 1761429600 (10/26/2025) |
| price_0day | $0-$5k | $0-$5k |
| cve_nvd_summary | A vulnerability was detected in code-projects Simple Food Ordering System 1.0. The affected element is an unknown function of the file /editproduct.php. Performing manipulation of the argument pname/category/price results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may be used. | |
| cvss4_cna_av | N | |
| cvss4_cna_ac | L | |
| cvss4_cna_at | N | |
| cvss4_cna_pr | N | |
| cvss4_cna_ui | P | |
| cvss4_cna_vc | N | |
| cvss4_cna_vi | L | |
| cvss4_cna_va | N | |
| cvss4_cna_sc | N | |
| cvss4_cna_si | N | |
| cvss4_cna_sa | N | |
| cvss4_cna_bscore | 5.3 | |
| cvss3_cna_av | N | |
| cvss3_cna_ac | L | |
| cvss3_cna_pr | N | |
| cvss3_cna_ui | R | |
| cvss3_cna_s | U | |
| cvss3_cna_c | N | |
| cvss3_cna_i | L | |
| cvss3_cna_a | N | |
| cvss3_cna_basescore | 4.3 | |
| cvss2_cna_av | N | |
| cvss2_cna_ac | L | |
| cvss2_cna_au | N | |
| cvss2_cna_ci | N | |
| cvss2_cna_ii | P | |
| cvss2_cna_ai | N | |
| cvss2_cna_basescore | 5 |