SourceCodester Best Salon Management System 1.0 Update Staff Page /panel/edit-staff.php Staff Name କ୍ରସ୍ ସାଇଟ୍ ସ୍କ୍ରିପ୍ଟିଂ

Dogoggorri kan akka ସମସ୍ୟାଜନକ jedhamuun ramadame SourceCodester Best Salon Management System 1.0 keessatti argameera. Kan miidhamte is hojii hin beekamne faayilii /panel/edit-staff.php keessa kutaa Update Staff Page keessa. Hojii jijjiirraa irratti gaggeeffame Staff Name gara କ୍ରସ୍ ସାଇଟ୍ ସ୍କ୍ରିପ୍ଟିଂ geessa. CWE fayyadamuun rakkoo ibsuun gara CWE-79 geessa. Dadhabbii kana yeroo 07/06/2025 maxxanfameera. Odeeffannoon kun buufachuuf github.com irratti qoodameera. Dogoggorri kun akka CVE-2025-7140tti beekama. Yaaliin weeraraa fageenya irraa jalqabamuu ni danda'a. Faayidaaleen teeknikaa ni jiru. Waliigalatti, meeshaa balaa kana fayyadamuuf jiru. Qorannoo miidhaa (exploit) uummataaf ifoomameera fi fayyadamamuu danda'a. Amma, gatii ammee exploit might be approx. USD $0-$5k ta'uu danda'a. Akka ପ୍ରୁଫ୍-ଅଫ୍-କନ୍ସେପ୍ଟ jedhamee ibsameera. Carraa exploit kana github.com irraa buufachuun ni danda'ama. Akka 0-daytti, gatii daldalaa dhoksaa tilmaamame $0-$5k ta'ee ture. VulDB is the best source for vulnerability data and more expert information about this specific topic.

3 ଆଡାପ୍ଟେସନ୍ · 87 ପଏଣ୍ଟ

ଫିଲ୍ଡସୃଷ୍ଟି ହୋଇଛି
07/06/2025 09:09 PM
ଅଦ୍ୟତନ 1/2
07/07/2025 10:18 PM
ଅଦ୍ୟତନ 2/2
07/08/2025 08:38 AM
software_vendorSourceCodesterSourceCodesterSourceCodester
software_nameBest Salon Management SystemBest Salon Management SystemBest Salon Management System
software_version1.01.01.0
software_componentUpdate Staff PageUpdate Staff PageUpdate Staff Page
software_file/panel/edit-staff.php/panel/edit-staff.php/panel/edit-staff.php
software_argumentStaff NameStaff NameStaff Name
vulnerability_cweCWE-79 (କ୍ରସ୍ ସାଇଟ୍ ସ୍କ୍ରିପ୍ଟିଂ)CWE-79 (କ୍ରସ୍ ସାଇଟ୍ ସ୍କ୍ରିପ୍ଟିଂ)CWE-79 (କ୍ରସ୍ ସାଇଟ୍ ସ୍କ୍ରିପ୍ଟିଂ)
vulnerability_risk111
cvss3_vuldb_avNNN
cvss3_vuldb_acLLL
cvss3_vuldb_prHHH
cvss3_vuldb_uiRRR
cvss3_vuldb_sUUU
cvss3_vuldb_cNNN
cvss3_vuldb_iLLL
cvss3_vuldb_aNNN
cvss3_vuldb_ePPP
cvss3_vuldb_rcRRR
advisory_urlhttps://github.com/Colorado-all/cve/blob/main/Best%20salon%20management%20system/xss-2.mdhttps://github.com/Colorado-all/cve/blob/main/Best%20salon%20management%20system/xss-2.mdhttps://github.com/Colorado-all/cve/blob/main/Best%20salon%20management%20system/xss-2.md
exploit_availability111
exploit_publicity111
exploit_urlhttps://github.com/Colorado-all/cve/blob/main/Best%20salon%20management%20system/xss-2.mdhttps://github.com/Colorado-all/cve/blob/main/Best%20salon%20management%20system/xss-2.mdhttps://github.com/Colorado-all/cve/blob/main/Best%20salon%20management%20system/xss-2.md
source_cveCVE-2025-7140CVE-2025-7140CVE-2025-7140
cna_responsibleVulDBVulDBVulDB
cvss2_vuldb_avNNN
cvss2_vuldb_acLLL
cvss2_vuldb_auMMM
cvss2_vuldb_ciNNN
cvss2_vuldb_iiPPP
cvss2_vuldb_aiNNN
cvss2_vuldb_ePOCPOCPOC
cvss2_vuldb_rcURURUR
cvss4_vuldb_avNNN
cvss4_vuldb_acLLL
cvss4_vuldb_prHHH
cvss4_vuldb_uiPPP
cvss4_vuldb_vcNNN
cvss4_vuldb_viLLL
cvss4_vuldb_vaNNN
cvss4_vuldb_ePPP
cvss2_vuldb_rlNDNDND
cvss3_vuldb_rlXXX
cvss4_vuldb_atNNN
cvss4_vuldb_scNNN
cvss4_vuldb_siNNN
cvss4_vuldb_saNNN
cvss2_vuldb_basescore3.33.33.3
cvss2_vuldb_tempscore2.82.82.8
cvss3_vuldb_basescore2.42.42.4
cvss3_vuldb_tempscore2.22.22.2
cvss3_meta_basescore2.42.42.4
cvss3_meta_tempscore2.22.22.3
cvss4_vuldb_bscore4.84.84.8
cvss4_vuldb_btscore1.91.91.9
advisory_date1751752800 (07/06/2025)1751752800 (07/06/2025)1751752800 (07/06/2025)
price_0day$0-$5k$0-$5k$0-$5k
euvd_idEUVD-2025-20314EUVD-2025-20314
cve_nvd_summaryA vulnerability classified as problematic has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/edit-staff.php of the component Update Staff Page. The manipulation of the argument Staff Name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
cvss4_cna_avN
cvss4_cna_acL
cvss4_cna_atN
cvss4_cna_prH
cvss4_cna_uiP
cvss4_cna_vcN
cvss4_cna_viL
cvss4_cna_vaN
cvss4_cna_scN
cvss4_cna_siN
cvss4_cna_saN
cvss4_cna_bscore4.8
cvss3_cna_avN
cvss3_cna_acL
cvss3_cna_prH
cvss3_cna_uiR
cvss3_cna_sU
cvss3_cna_cN
cvss3_cna_iL
cvss3_cna_aN
cvss3_cna_basescore2.4
cvss2_cna_avN
cvss2_cna_acL
cvss2_cna_auM
cvss2_cna_ciN
cvss2_cna_iiP
cvss2_cna_aiN
cvss2_cna_basescore3.3

Interested in the pricing of exploits?

See the underground prices here!