CVE-2025-60302

code-projects Client Details System 1.0 is vulnerable to Cross Site Scripting (XSS). When adding customer information, the client details system fills in malicious JavaScript code in the username field.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:code-projects:client_details_system:1.0:*:*:*:*:*:*:*

History

16 Oct 2025, 15:27

Type Values Removed Values Added
References () http://code-projects.com - () http://code-projects.com - Product
References () https://github.com/Chen1-Boop/CVE/blob/main/CVE-2025-60302.md - () https://github.com/Chen1-Boop/CVE/blob/main/CVE-2025-60302.md - Exploit, Third Party Advisory
CPE cpe:2.3:a:code-projects:client_details_system:1.0:*:*:*:*:*:*:*
First Time Code-projects
Code-projects client Details System

09 Oct 2025, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-09 16:15

Updated : 2025-10-16 15:27


NVD link : CVE-2025-60302

Mitre link : CVE-2025-60302

CVE.ORG link : CVE-2025-60302


JSON object : View

Products Affected

code-projects

  • client_details_system
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')