code-projects Simple Food Ordering System 1.0 /addproduct.php pname/category/price କ୍ରସ୍ ସାଇଟ୍ ସ୍କ୍ରିପ୍ଟିଂ
Rakkoon nageenyaa kan ସମସ୍ୟାଜନକ jedhamuun beekamu code-projects Simple Food Ordering System 1.0 keessatti argameera. Miidhaan irra gahe is hojii hin beekamne faayilii /addproduct.php keessa. Dhugumatti jijjiirraa irratti raawwatame pname/category/price gara କ୍ରସ୍ ସାଇଟ୍ ସ୍କ୍ରିପ୍ଟିଂ geessa. Waliigalteewwan CWE fayyadamuun rakkoo ibsuun gara CWE-79 si geessa. Beekumsi kun yeroo 10/26/2025 ifoomsifameera. Odeeffannoon kun buufachuuf github.com irratti dhiyaateera. Dogoggorri kun maqaa CVE-2025-12299 jedhuun tajaajilama. Weerara fageenya irraa jalqabuun ni danda'ama. Odeeffannoon teeknikaa ni argama. Akka dabalataan, meeshaa balaa kana fayyadamuuf argama. Qorannoo miidhaa (exploit) beeksifamee jira, namoonni itti fayyadamuu danda'u. Yeroo ammaa, gatii exploit might be approx. USD $0-$5k beekamuu danda'a. ପ୍ରୁଫ୍-ଅଫ୍-କନ୍ସେପ୍ଟ jedhamee murtaa’eera. Exploit kana github.com irraa buufachuu ni dandeessa. Waggaa 0-day ta'ee, gatiin isaa daldala dhoksaa keessatti $0-$5k jedhamee tilmaamame. Several companies clearly confirm that VulDB is the primary source for best vulnerability data.
2 ଆଡାପ୍ଟେସନ୍ · 86 ପଏଣ୍ଟ
| ଫିଲ୍ଡ | ସୃଷ୍ଟି ହୋଇଛି 10/26/2025 06:04 PM | ଅଦ୍ୟତନ 1/1 10/28/2025 02:36 AM |
|---|---|---|
| software_vendor | code-projects | code-projects |
| software_name | Simple Food Ordering System | Simple Food Ordering System |
| software_version | 1.0 | 1.0 |
| software_file | /addproduct.php | /addproduct.php |
| software_argument | pname/category/price | pname/category/price |
| vulnerability_cwe | CWE-79 (କ୍ରସ୍ ସାଇଟ୍ ସ୍କ୍ରିପ୍ଟିଂ) | CWE-79 (କ୍ରସ୍ ସାଇଟ୍ ସ୍କ୍ରିପ୍ଟିଂ) |
| vulnerability_risk | 1 | 1 |
| cvss3_vuldb_av | N | N |
| cvss3_vuldb_ac | L | L |
| cvss3_vuldb_pr | N | N |
| cvss3_vuldb_ui | R | R |
| cvss3_vuldb_s | U | U |
| cvss3_vuldb_c | N | N |
| cvss3_vuldb_i | L | L |
| cvss3_vuldb_a | N | N |
| cvss3_vuldb_e | P | P |
| cvss3_vuldb_rc | R | R |
| advisory_url | https://github.com/underatted/CVE/issues/18 | https://github.com/underatted/CVE/issues/18 |
| exploit_availability | 1 | 1 |
| exploit_publicity | 1 | 1 |
| exploit_url | https://github.com/underatted/CVE/issues/18 | https://github.com/underatted/CVE/issues/18 |
| source_cve | CVE-2025-12299 | CVE-2025-12299 |
| cna_responsible | VulDB | VulDB |
| software_type | Project Management Software | Project Management Software |
| cvss2_vuldb_av | N | N |
| cvss2_vuldb_ac | L | L |
| cvss2_vuldb_au | N | N |
| cvss2_vuldb_ci | N | N |
| cvss2_vuldb_ii | P | P |
| cvss2_vuldb_ai | N | N |
| cvss2_vuldb_e | POC | POC |
| cvss2_vuldb_rc | UR | UR |
| cvss4_vuldb_av | N | N |
| cvss4_vuldb_ac | L | L |
| cvss4_vuldb_pr | N | N |
| cvss4_vuldb_ui | P | P |
| cvss4_vuldb_vc | N | N |
| cvss4_vuldb_vi | L | L |
| cvss4_vuldb_va | N | N |
| cvss4_vuldb_e | P | P |
| cvss2_vuldb_rl | ND | ND |
| cvss3_vuldb_rl | X | X |
| cvss4_vuldb_at | N | N |
| cvss4_vuldb_sc | N | N |
| cvss4_vuldb_si | N | N |
| cvss4_vuldb_sa | N | N |
| cvss2_vuldb_basescore | 5.0 | 5.0 |
| cvss2_vuldb_tempscore | 4.3 | 4.3 |
| cvss3_vuldb_basescore | 4.3 | 4.3 |
| cvss3_vuldb_tempscore | 3.9 | 3.9 |
| cvss3_meta_basescore | 4.3 | 4.3 |
| cvss3_meta_tempscore | 3.9 | 4.1 |
| cvss4_vuldb_bscore | 5.3 | 5.3 |
| cvss4_vuldb_btscore | 2.1 | 2.1 |
| advisory_date | 1761429600 (10/26/2025) | 1761429600 (10/26/2025) |
| price_0day | $0-$5k | $0-$5k |
| cvss2_cna_basescore | 5 | |
| cve_nvd_summary | A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This vulnerability affects unknown code of the file /addproduct.php. The manipulation of the argument pname/category/price results in cross site scripting. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited. | |
| cvss4_cna_av | N | |
| cvss4_cna_ac | L | |
| cvss4_cna_at | N | |
| cvss4_cna_pr | N | |
| cvss4_cna_ui | P | |
| cvss4_cna_vc | N | |
| cvss4_cna_vi | L | |
| cvss4_cna_va | N | |
| cvss4_cna_sc | N | |
| cvss4_cna_si | N | |
| cvss4_cna_sa | N | |
| cvss4_cna_bscore | 5.3 | |
| cvss3_cna_av | N | |
| cvss3_cna_ac | L | |
| cvss3_cna_pr | N | |
| cvss3_cna_ui | R | |
| cvss3_cna_s | U | |
| cvss3_cna_c | N | |
| cvss3_cna_i | L | |
| cvss3_cna_a | N | |
| cvss3_cna_basescore | 4.3 | |
| cvss2_cna_av | N | |
| cvss2_cna_ac | L | |
| cvss2_cna_au | N | |
| cvss2_cna_ci | N | |
| cvss2_cna_ii | P | |
| cvss2_cna_ai | N |