Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-40641

Опубликовано: 08 сент. 2025
Источник: nvd
EPSS Низкий

Описание

Cross-site Scripting (XSS) vulnerability stored in Multi-Purpose Inventory Management System, consisting of a stored XSS due to lack of proper validation of user input by sending a POST request using the product_name parameter in /Controller_Products/update. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal their cookie session details.

EPSS

Процентиль: 37%
0.0016
Низкий

Дефекты

CWE-79

Связанные уязвимости

github
5 месяцев назад

Cross-site Scripting (XSS) vulnerability stored in Multi-Purpose Inventory Management System, consisting of a stored XSS due to lack of proper validation of user input by sending a POST request using the product_name parameter in /Controller_Products/update. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal their cookie session details.

EPSS

Процентиль: 37%
0.0016
Низкий

Дефекты

CWE-79