CVE-2025-7140: SourceCodester Best Salon Management System Update Staff Page edit-staff.php cross site scripting
A vulnerability classified as problematic has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/edit-staff.php of the component Update Staff Page. The manipulation of the argument Staff Name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7140?
CVE-2025-7140 is classified as a problematic vulnerability.
How do I fix CVE-2025-7140?
To fix CVE-2025-7140, ensure proper sanitation and validation of the Staff Name input to prevent cross-site scripting.
Which component is affected by CVE-2025-7140?
CVE-2025-7140 affects the Update Staff Page component in the SourceCodester Best Salon Management System.
What is the potential impact of CVE-2025-7140?
The exploitation of CVE-2025-7140 can lead to cross-site scripting attacks which may compromise user data.
In which file is CVE-2025-7140 located?
CVE-2025-7140 is located in the file /panel/edit-staff.php.