CVE-2025-9440: 1000projects Online Project Report Submission and Evaluation System add_title.php cross site scripting
A security vulnerability has been detected in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected by this issue is some unknown functionality of the file /admin/addtitle.php. Such manipulation of the argument Title leads to cross site scripting. The attack may be performed from a remote location. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9440?
CVE-2025-9440 has been classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2025-9440?
To remediate CVE-2025-9440, ensure that proper input validation and sanitization are implemented for the Title parameter in the /admin/add_title.php file.
Which versions of the software are affected by CVE-2025-9440?
CVE-2025-9440 affects version 1.0 of the 1000projects Online Project Report Submission and Evaluation System.
What type of vulnerability is CVE-2025-9440?
CVE-2025-9440 is a cross-site scripting (XSS) vulnerability that can be exploited through improper handling of user input.
Where does CVE-2025-9440 occur in the software?
CVE-2025-9440 is detected in the /admin/add_title.php functionality of the 1000projects Online Project Report Submission and Evaluation System.