CVE-2025-10075: SourceCodester Online Polling System manage-profile.php cross site scripting
A security flaw has been discovered in SourceCodester Online Polling System 1.0. The impacted element is an unknown function of the file /manage-profile.php. The manipulation of the argument firstname results in cross site scripting. The attack can be launched remotely. The exploit has been released to the public and may be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10075?
CVE-2025-10075 has a high severity rating due to its potential for remote exploitation and cross-site scripting vulnerabilities.
How do I fix CVE-2025-10075?
To fix CVE-2025-10075, sanitize and validate user input in the manage-profile.php file to prevent cross-site scripting.
Which systems are affected by CVE-2025-10075?
CVE-2025-10075 affects the SourceCodester Online Polling System version 1.0.
Can CVE-2025-10075 be exploited remotely?
Yes, CVE-2025-10075 can be exploited remotely by manipulating the firstname argument.
What type of vulnerability is CVE-2025-10075?
CVE-2025-10075 is a cross-site scripting (XSS) vulnerability.