CVE-2025-9929: code-projects Responsive Blog Site blogs_view.php cross site scripting
A weakness has been identified in code-projects Responsive Blog Site 1.0. This affects an unknown function of the file blogsview.php. Executing manipulation of the argument productcode/genname/productname/supplier can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been made available to the public and could be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9929?
CVE-2025-9929 has been assessed as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2025-9929?
To fix CVE-2025-9929, sanitize and validate user inputs for the parameters product_code, gen_name, product_name, and supplier in the blogs_view.php file.
What vulnerabilities are associated with CVE-2025-9929?
CVE-2025-9929 specifically relates to a weakness in code-projects Responsive Blog Site that allows cross-site scripting through manipulation of certain URL parameters.
What are the potential impacts of exploiting CVE-2025-9929?
Exploitation of CVE-2025-9929 can lead to the execution of arbitrary scripts in the context of another user's session, compromising sensitive information.
Who is affected by CVE-2025-9929?
Any users of code-projects Responsive Blog Site version 1.0 that utilize the blogs_view.php file are vulnerable to CVE-2025-9929.