CVE-2025-50869

A stored Cross-Site Scripting (XSS) vulnerability exists in the qureydetails.php page of Institute-of-Current-Students 1.0, where the input fields for Query and Answer do not properly sanitize user input. Authenticated users can inject arbitrary JavaScript code.
Configurations

No configuration.

History

04 Aug 2025, 15:06

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de Cross-Site Scripting (XSS) almacenado en la página qureydetails.php de Institute-of-Current-Students 1.0, donde los campos de consulta y respuesta no depuran correctamente la entrada del usuario. Los usuarios autenticados pueden inyectar código JavaScript arbitrario.

01 Aug 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-01 18:15

Updated : 2025-08-04 15:06


NVD link : CVE-2025-50869

Mitre link : CVE-2025-50869

CVE.ORG link : CVE-2025-50869


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')