Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12458 | A vulnerability classified as problematic was found in withstars Books-Management-System 1.0. This vulnerability affects unknown code of the file /api/comment/add of the component Comment Handler. The manipulation of the argument content leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 12 May 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Withstars
Withstars books-management-system |
|
| CPEs | cpe:2.3:a:withstars:books-management-system:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Withstars
Withstars books-management-system |
Mon, 28 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 27 Apr 2025 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability classified as problematic was found in withstars Books-Management-System 1.0. This vulnerability affects unknown code of the file /api/comment/add of the component Comment Handler. The manipulation of the argument content leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer. | |
| Title | withstars Books-Management-System Comment add cross site scripting | |
| Weaknesses | CWE-79 CWE-94 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-04-28T14:25:57.360Z
Reserved: 2025-04-26T07:03:35.605Z
Link: CVE-2025-3962
Updated: 2025-04-28T14:25:53.048Z
Status : Analyzed
Published: 2025-04-27T07:15:15.580
Modified: 2025-05-12T19:09:31.443
Link: CVE-2025-3962
No data.
OpenCVE Enrichment
No data.
EUVD