CVE-2025-12228: projectworlds Expense Management System Users Page create cross site scripting
A vulnerability was identified in projectworlds Expense Management System 1.0. The impacted element is an unknown function of the file /public/admin/users/create of the component Users Page. The manipulation leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12228?
The severity of CVE-2025-12228 is classified as high due to its potential for cross-site scripting attacks.
How do I fix CVE-2025-12228?
To remediate CVE-2025-12228, ensure input sanitization and validation are implemented properly in the affected users create function.
Can CVE-2025-12228 be exploited remotely?
Yes, CVE-2025-12228 can be exploited remotely, allowing attackers to execute scripts in the context of the user's session.
Which components are affected by CVE-2025-12228?
CVE-2025-12228 specifically affects the Users Page component of the Projectworlds Expense Management System 1.0.
What are the potential consequences of CVE-2025-12228?
Exploitation of CVE-2025-12228 can lead to unauthorized actions being performed on behalf of a user, compromising user data and security.