Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 05 Jan 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Slims Project
Slims Project slims |
|
| CPEs | cpe:2.3:a:slims_project:slims:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Slims Project
Slims Project slims |
Thu, 18 Dec 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Slims
Slims slims 9 Bulian |
|
| Vendors & Products |
Slims
Slims slims 9 Bulian |
Wed, 17 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Wed, 17 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF' ] in index.php/sysconfig.inc.php, which allows remote attackers to execute arbitrary JavaScript in a victim's browser by supplying a crafted URL path. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-17T20:48:22.913Z
Reserved: 2025-11-18T00:00:00.000Z
Link: CVE-2025-65233
Updated: 2025-12-17T20:46:50.375Z
Status : Analyzed
Published: 2025-12-17T20:15:55.647
Modified: 2026-01-05T14:26:20.110
Link: CVE-2025-65233
No data.
OpenCVE Enrichment
Updated: 2025-12-18T09:56:58Z