CVE-2025-12230: projectworlds Expense Management System Currency create cross site scripting
A weakness has been identified in projectworlds Expense Management System 1.0. This impacts an unknown function of the file /public/admin/currencies/create of the component Currency Page. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12230?
CVE-2025-12230 has been classified as a high severity vulnerability due to its potential for remote exploitation through cross-site scripting.
How do I fix CVE-2025-12230?
To remediate CVE-2025-12230, validate and sanitize all user input on the Currency Page to prevent cross-site scripting attacks.
What is affected by CVE-2025-12230?
CVE-2025-12230 affects the Currency Page component of the Projectworlds Expense Management System version 1.0.
Can CVE-2025-12230 be exploited remotely?
Yes, CVE-2025-12230 can be exploited remotely, allowing attackers to execute malicious scripts in a victim's browser.
What is the nature of the vulnerability in CVE-2025-12230?
CVE-2025-12230 involves a cross-site scripting vulnerability that allows manipulation of user input in an unknown function.