CVE-2025-1209: code-projects Wazifa System search_resualts.php searchuser cross site scripting
A vulnerability classified as problematic has been found in code-projects Wazifa System 1.0. Affected is the function searchuser of the file /searchresualts.php. The manipulation of the argument firstname/lastname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. There is a typo in the affected file name.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1209?
The severity of CVE-2025-1209 is classified as problematic due to its potential for cross-site scripting vulnerabilities.
How do I fix CVE-2025-1209?
To fix CVE-2025-1209, you need to sanitize and validate user input in the searchuser function to prevent XSS attacks.
Which software is affected by CVE-2025-1209?
CVE-2025-1209 affects Wazifa System version 1.0 developed by code-projects.
What type of vulnerability is CVE-2025-1209?
CVE-2025-1209 is a cross-site scripting (XSS) vulnerability.
Where in the code is CVE-2025-1209 located?
CVE-2025-1209 is located in the searchuser function of the file /search_results.php.