CVE-2025-12282: code-projects Client Details System manage-users.php cross site scripting
Published Oct 27, 2025
·Updated
A vulnerability was identified in code-projects Client Details System 1.0. The affected element is an unknown function of the file /admin/manage-users.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used.
Affected Software
2 affected components
Code-projects Client Details System
Fabian Client Details System=1.0
Event History
Oct 27, 2025
CVE Published
via MITRE·01:32 PM
Data Sourced
via MITRE·01:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-12282?
CVE-2025-12282 is classified as a cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2025-12282?
To fix CVE-2025-12282, validate and sanitize user inputs in the '/admin/manage-users.php' file.
3
Can CVE-2025-12282 be exploited remotely?
Yes, CVE-2025-12282 can be exploited remotely by an attacker.
4
What software is affected by CVE-2025-12282?
CVE-2025-12282 affects the Code-projects Client Details System version 1.0.
5
Is there a patch available for CVE-2025-12282?
As of now, a specific patch for CVE-2025-12282 has not been provided.