CVE-2025-12335: code-projects E-Commerce Website supplier_update.php cross site scripting
A vulnerability was determined in code-projects E-Commerce Website 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/supplierupdate.php. This manipulation of the argument suppname/suppaddress causes cross site scripting. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12335?
CVE-2025-12335 is classified as a cross-site scripting vulnerability that could allow an attacker to manipulate the application.
How do I fix CVE-2025-12335?
To fix CVE-2025-12335, properly sanitize and validate user inputs in the affected file /pages/supplier_update.php.
What impacts does CVE-2025-12335 have?
CVE-2025-12335 can lead to unauthorized script execution in the context of users' browsers, potentially compromising user data.
Which software is affected by CVE-2025-12335?
The vulnerability CVE-2025-12335 affects Code-projects E-Commerce Website version 1.0.
How can I detect CVE-2025-12335 in my application?
You can detect CVE-2025-12335 by testing the application for cross-site scripting vulnerabilities specifically in the supplier update functionality.