CVE-2025-0301

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Jan 7, 2025
Updated: Feb 26, 2025
CWE ID 94
CWE ID 79

Summary

CVE-2025-0301 is a newly disclosed vulnerability affecting the code-projects Online Book Shop 1.0. This issue lies within the unknown functionality of the file /subcat.php, specifically related to the handling of the argument catnm. An attacker can exploit this cross-site scripting (XSS) vulnerability to inject malicious code, potentially gaining unauthorized access to user data or taking control of the affected system. The exploit has been made public, increasing the risk of widespread attacks. Users are urged to apply patches or updates as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share