Description
Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Ticket Booking System v1.0 allows an attacker to execute arbitrary code into the Full Name and Address fields during user registration or profile editing.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12589 | Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Ticket Booking System v1.0 allows an attacker to execute arbitrary code into the Full Name and Address fields during user registration or profile editing. |
References
History
Wed, 30 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Codeastro
Codeastro bus Ticket Booking System |
|
| CPEs | cpe:2.3:a:codeastro:bus_ticket_booking_system:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Codeastro
Codeastro bus Ticket Booking System |
Mon, 28 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Mon, 28 Apr 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Ticket Booking System v1.0 allows an attacker to execute arbitrary code into the Full Name and Address fields during user registration or profile editing. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-28T17:36:45.256Z
Reserved: 2025-02-07T00:00:00.000Z
Link: CVE-2025-25776
Updated: 2025-04-28T17:36:38.731Z
Status : Analyzed
Published: 2025-04-28T15:15:45.587
Modified: 2025-04-30T18:58:22.110
Link: CVE-2025-25776
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD