CVE-2025-12229: projectworlds Expense Management System Roles Page create cross site scripting
A security flaw has been discovered in projectworlds Expense Management System 1.0. This affects an unknown function of the file /public/admin/roles/create of the component Roles Page. The manipulation results in cross site scripting. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12229?
CVE-2025-12229 has been classified as a medium-severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2025-12229?
To fix CVE-2025-12229, ensure proper input validation and output encoding in the affected roles creation functionality.
What type of vulnerability is CVE-2025-12229?
CVE-2025-12229 is a cross-site scripting (XSS) vulnerability that affects the Roles Page of the Expense Management System.
Is CVE-2025-12229 exploitable remotely?
Yes, CVE-2025-12229 can be exploited remotely by an attacker through crafted inputs to the roles creation function.
What software is affected by CVE-2025-12229?
CVE-2025-12229 affects version 1.0 of the Projectworlds Expense Management System.