CVE-2025-10088: SourceCodester Time Tracker index.html cross site scripting
A vulnerability was detected in SourceCodester Time Tracker 1.0. The affected element is an unknown function of the file /index.html. Performing manipulation of the argument project-name results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10088?
CVE-2025-10088 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2025-10088?
To fix CVE-2025-10088, sanitize and validate the input for the 'project-name' parameter to prevent malicious scripts.
What type of vulnerability is CVE-2025-10088?
CVE-2025-10088 is categorized as a cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2025-10088?
Users of SourceCodester Time Tracker 1.0 are affected by CVE-2025-10088.
Can CVE-2025-10088 be exploited remotely?
Yes, CVE-2025-10088 can be exploited remotely by manipulating the 'project-name' argument.