CVE-2025-12231: projectworlds Expense Management System Expense Categories create cross site scripting
A security vulnerability has been detected in projectworlds Expense Management System 1.0. Affected is an unknown function of the file /public/admin/expensecategories/create of the component Expense Categories Page. Such manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12231?
CVE-2025-12231 is classified as a medium severity cross-site scripting vulnerability.
How do I fix CVE-2025-12231?
To fix CVE-2025-12231, ensure proper input validation and output encoding to prevent script injection in the Expense Categories Page.
What components are affected by CVE-2025-12231?
CVE-2025-12231 affects the Expense Categories Page in the projectworlds Expense Management System 1.0.
What type of vulnerability is CVE-2025-12231?
CVE-2025-12231 is a cross-site scripting (XSS) vulnerability that can be exploited through inadequate sanitization of input.
What actions are possible due to CVE-2025-12231?
Due to CVE-2025-12231, an attacker can manipulate the affected function to execute arbitrary JavaScript in the user's browser.