CVE-2025-0342

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jan 9, 2025
Updated: Mar 3, 2025
CWE ID 94
CWE ID 79

Summary

CVE-2025-0342 is a newly disclosed vulnerability affecting the CampCodes Computer Laboratory Management System version 1.0. The issue lies within the /class/edit/edit file, where the argument s_lname is susceptible to cross-site scripting (XSS) attacks. An attacker can exploit this remotely by manipulating this argument, potentially leading to code injection and data theft. The exploit has been made public, increasing the risk of widespread attacks. Other parameters of the system may also be vulnerable to similar attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share