code-projects Client Details System 1.0 is vulnerable to Cross Site Scripting (XSS). When adding customer information, the client details system fills in malicious JavaScript code in the username field.
References
Link | Resource |
---|---|
http://code-projects.com | Product |
https://github.com/Chen1-Boop/CVE/blob/main/CVE-2025-60302.md | Exploit Third Party Advisory |
Configurations
History
16 Oct 2025, 15:27
Type | Values Removed | Values Added |
---|---|---|
References | () http://code-projects.com - Product | |
References | () https://github.com/Chen1-Boop/CVE/blob/main/CVE-2025-60302.md - Exploit, Third Party Advisory | |
CPE | cpe:2.3:a:code-projects:client_details_system:1.0:*:*:*:*:*:*:* | |
First Time |
Code-projects
Code-projects client Details System |
09 Oct 2025, 17:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-10-09 16:15
Updated : 2025-10-16 15:27
NVD link : CVE-2025-60302
Mitre link : CVE-2025-60302
CVE.ORG link : CVE-2025-60302
JSON object : View
Products Affected
code-projects
- client_details_system
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')