CVE-2025-60318: XSS
Published Oct 8, 2025
·Updated
SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the fname (First Name) and lname (Last Name) fields.
Affected Software
2 affected components
Sourcecodester Pet Grooming Management Software
Mayurik Pet Grooming Management Software=1.0
Event History
Oct 8, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-60318?
CVE-2025-60318 has a medium severity level due to its potential for Cross Site Scripting (XSS) attacks.
2
How do I fix CVE-2025-60318?
To fix CVE-2025-60318, ensure proper sanitization and validation of user input in the fname and lname fields.
3
What type of vulnerability is CVE-2025-60318?
CVE-2025-60318 is classified as a Cross Site Scripting (XSS) vulnerability.
4
Which application is affected by CVE-2025-60318?
CVE-2025-60318 affects SourceCodester Pet Grooming Management Software version 1.0.
5
How can CVE-2025-60318 be exploited?
CVE-2025-60318 can be exploited by injecting malicious scripts through the firstname and lastname form fields.