CVE-2025-0348

CVSS 3.1 Score 3.5 of 10 (low)

Details

Published Jan 9, 2025
CWE ID 94
CWE ID 79

Summary

CVE-2025-0348 is a recently disclosed vulnerability affecting the CampCodes DepEd Equipment Inventory System 1.0. This issue, which has been classified as problematic, allows for cross-site scripting attacks. The vulnerability is located in the /data/add_employee.php file and can be exploited by manipulating argument data. An attacker can initiate the exploit remotely, potentially leading to security breaches and unauthorized access to user data. The public disclosure of this exploit increases the risk of its widespread use.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share