CVE-2025-63640: XSS
Sourcecodester Medicine Reminder App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Medicine Name" and "Notes (Optional)" fields when creating an "Upcoming Reminder", allowing an attacker to inject arbitrary potentially malicious HTML/JavaScript code that executes in the victim's browser upon clicking the "Save Reminder" button.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-63640?
CVE-2025-63640 is categorized as a high severity vulnerability due to its potential for malicious code execution in user browsers.
How can I mitigate CVE-2025-63640?
To fix CVE-2025-63640, ensure proper input validation and escaping of user inputs in the "Medicine Name" and "Notes (Optional)" fields.
What type of vulnerability is CVE-2025-63640?
CVE-2025-63640 is a Cross-Site Scripting (XSS) vulnerability affecting the Medicine Reminder App.
What are the potential effects of CVE-2025-63640?
Exploitation of CVE-2025-63640 could allow attackers to execute arbitrary JavaScript code in the context of the victim's browser.
Which version of the Medicine Reminder App is affected by CVE-2025-63640?
CVE-2025-63640 affects version 1.0 of the Sourcecodester Medicine Reminder App.