First published: Fri Jan 17 2025(Updated: )
A vulnerability, which was classified as problematic, was found in code-projects Tourism Management System 1.0. Affected is an unknown function of the file /admin/manage-pages.php. The manipulation of the argument pgedetails leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tourism Management System | ||
Fabianros Tourism Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0538 is classified as a problematic vulnerability.
CVE-2025-0538 is a Cross-Site Scripting (XSS) vulnerability affecting the manage-pages.php file.
CVE-2025-0538 allows attackers to manipulate the pgedetails parameter, potentially leading to unauthorized script execution.
To fix CVE-2025-0538, ensure proper sanitization and validation of user inputs in the affected components.
CVE-2025-0538 affects the code-projects Tourism Management System version 1.0.