First published: Tue Feb 11 2025(Updated: )
A vulnerability has been found in 1000 Projects Bookstore Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file process_book_add.php of the component Add Book Page. The manipulation of the argument Book Name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
1000projects Bookstore Management System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1174 is classified as a problematic vulnerability that could lead to cross-site scripting attacks.
To fix CVE-2025-1174, ensure proper input validation and output encoding for the Book Name parameter in process_book_add.php.
CVE-2025-1174 affects the Add Book Page component of the 1000 Projects Bookstore Management System.
CVE-2025-1174 affects version 1.0 of the 1000 Projects Bookstore Management System.
CVE-2025-1174 enables cross-site scripting (XSS) attacks through the manipulation of user input.