CVE-2025-1114

medium

Description

A vulnerability classified as problematic has been found in newbee-mall 1.0. Affected is the function save of the file /admin/categories/save of the component Add Category Page. The manipulation of the argument categoryName leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.

References

https://vuldb.com/?submit.489744

https://vuldb.com/?id.295020

https://vuldb.com/?ctiid.295020

https://github.com/newbee-ltd/newbee-mall/issues/94#issue-2811680280

https://github.com/newbee-ltd/newbee-mall/issues/94

Details

Source: Mitre, NVD

Published: 2025-02-07

Updated: 2025-02-10

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 3.5

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

Severity: Low

CVSS v4

Base Score: 5.1

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Severity: Medium