CVE-2025-3692: SourceCodester Online Eyewear Shop Master.php cross site scripting
A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /oews/classes/Master.php?f=saveproduct. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3692?
CVE-2025-3692 is classified as a high severity vulnerability due to its potential for cross-site scripting attacks.
What type of vulnerability is CVE-2025-3692?
CVE-2025-3692 is a cross-site scripting (XSS) vulnerability affecting the save_product functionality.
How does CVE-2025-3692 affect users?
CVE-2025-3692 can allow attackers to inject malicious scripts into web pages viewed by users, compromising their data.
How do I fix CVE-2025-3692?
To mitigate CVE-2025-3692, implement proper input validation and output encoding on the affected functionality.
Which software is impacted by CVE-2025-3692?
CVE-2025-3692 affects the SourceCodester Online Eyewear Shop version 1.0.