CVE-2025-29710: XSS
Published Apr 16, 2025
·Updated
SourceCodester Company Website CMS 1.0 is vulnerable to Cross Site Scripting (XSS) via /dashboard/Services.
Affected Software
2 affected components
Sourcecodester Company Website CMS
Torrahclef Company Website Cms=1.0
Event History
Apr 16, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-29710?
CVE-2025-29710 has a high severity rating due to its potential for exploitation through Cross Site Scripting (XSS).
2
How do I fix CVE-2025-29710?
To fix CVE-2025-29710, apply input validation and output encoding to sanitize user inputs in the /dashboard/Services path.
3
What types of systems are affected by CVE-2025-29710?
CVE-2025-29710 affects SourceCodester Company Website CMS version 1.0 and potentially other similar configurations.
4
What can an attacker do with CVE-2025-29710?
An attacker can exploit CVE-2025-29710 to execute arbitrary scripts in the context of the user's browser, leading to data theft or session hijacking.
5
Is there a patch available for CVE-2025-29710?
As of now, there is no official patch available for CVE-2025-29710, so it is recommended to implement a workaround until a fix is released.