First published: Sat Apr 05 2025(Updated: )
A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /classes/Master.php?f=save_product. The manipulation of the argument brand leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
SourceCodester Online Eyewear Shop | ||
SourceCodester Online Eyewear Shop | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3297 is classified as a problematic vulnerability due to its potential for cross site scripting.
To fix CVE-2025-3297, ensure proper validation and sanitization of user input in the /classes/Master.php file.
CVE-2025-3297 affects SourceCodester Online Eyewear Shop version 1.0.
CVE-2025-3297 enables cross site scripting (XSS) attacks through the manipulation of the brand argument.
CVE-2025-3297 is associated with the file /classes/Master.php in the affected software.