CVE-2025-65215: XSS
Sourcecodester Web-based Pharmacy Product Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /productexpiry/add-supplier.php via the Supplier Name field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-65215?
CVE-2025-65215 is classified as a medium severity vulnerability due to its potential impact on user sessions and data through XSS attacks.
How do I fix CVE-2025-65215?
To fix CVE-2025-65215, sanitize and validate the input for the Supplier Name field to prevent injection of malicious scripts.
What types of attacks can CVE-2025-65215 lead to?
CVE-2025-65215 can lead to cross-site scripting (XSS) attacks, allowing attackers to execute scripts in the user's browser.
Who is affected by CVE-2025-65215?
CVE-2025-65215 affects users of the Sourcecodester Web-based Pharmacy Product Management System v1.0.
What should I do if I am using an affected version related to CVE-2025-65215?
If you are using a vulnerable version, it is recommended to upgrade to a patched version or implement input validation measures immediately.