CVE-2025-10631: itsourcecode Online Petshop Management System Available Products addcnp.php cross site scripting
A vulnerability was identified in itsourcecode Online Petshop Management System 1.0. Impacted is an unknown function of the file addcnp.php of the component Available Products Page. The manipulation of the argument name/description leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10631?
The severity of CVE-2025-10631 is currently assessed as moderate due to its potential for cross-site scripting exploitation.
How do I fix CVE-2025-10631?
To fix CVE-2025-10631, validate and sanitize input on the addcnp.php page, specifically the name and description arguments.
What types of attacks can CVE-2025-10631 lead to?
CVE-2025-10631 can lead to cross-site scripting (XSS) attacks, compromising user data and session integrity.
Is CVE-2025-10631 easy to exploit?
Yes, CVE-2025-10631 can be easily exploited if proper input validation measures are not implemented.
Which version of the Online Petshop Management System is affected by CVE-2025-10631?
CVE-2025-10631 affects version 1.0 of the itsourcecode Online Petshop Management System.