CVE-2025-3297: SourceCodester Online Eyewear Shop Master.php cross site scripting
A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /classes/Master.php?f=saveproduct. The manipulation of the argument brand leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3297?
CVE-2025-3297 is classified as a problematic vulnerability due to its potential for cross site scripting.
How do I fix CVE-2025-3297?
To fix CVE-2025-3297, ensure proper validation and sanitization of user input in the /classes/Master.php file.
Which software is affected by CVE-2025-3297?
CVE-2025-3297 affects SourceCodester Online Eyewear Shop version 1.0.
What type of attack does CVE-2025-3297 enable?
CVE-2025-3297 enables cross site scripting (XSS) attacks through the manipulation of the brand argument.
What file is associated with CVE-2025-3297?
CVE-2025-3297 is associated with the file /classes/Master.php in the affected software.