CVE-2025-12299: code-projects Simple Food Ordering System addproduct.php cross site scripting
A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This vulnerability affects unknown code of the file /addproduct.php. The manipulation of the argument pname/category/price results in cross site scripting. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12299?
CVE-2025-12299 has a medium severity level due to its potential for cross-site scripting attacks.
How do I fix CVE-2025-12299?
To fix CVE-2025-12299, validate and sanitize input in the /addproduct.php file to prevent XSS vulnerabilities.
What impact does CVE-2025-12299 have on my application?
CVE-2025-12299 can allow attackers to inject malicious scripts, compromising the integrity and security of the application.
Who is affected by CVE-2025-12299?
CVE-2025-12299 affects users of Code-projects Simple Food Ordering System version 1.0.
Is CVE-2025-12299 a remote attack vector?
Yes, CVE-2025-12299 can be exploited remotely by manipulating certain input parameters.