CVE-2025-8934: 1000 Projects Sales Management System sales.php cross site scripting
A vulnerability has been found in 1000 Projects Sales Management System 1.0. Affected is an unknown function of the file /sales.php. The manipulation of the argument select2112 leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8934?
CVE-2025-8934 has been categorized as a high-severity cross-site scripting vulnerability.
How do I fix CVE-2025-8934?
To fix CVE-2025-8934, sanitize and validate user inputs in the /sales.php file to prevent cross-site scripting.
What products are affected by CVE-2025-8934?
CVE-2025-8934 affects version 1.0 of the 1000 Projects Sales Management System.
Can CVE-2025-8934 be exploited remotely?
Yes, CVE-2025-8934 can be exploited remotely due to its nature of cross-site scripting.
What type of vulnerability is CVE-2025-8934?
CVE-2025-8934 is classified as a cross-site scripting (XSS) vulnerability.