CVE-2025-1174

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Feb 11, 2025
Updated: Feb 28, 2025
CWE ID 94
CWE ID 79

Summary

CVE-2025-1174 is a newly disclosed vulnerability affecting the Add Book Page component of 1000 Projects Bookstore Management System 1.0. The issue lies in the process_book_add.php file and involves cross-site scripting (XSS) due to improper validation of user input, specifically the Book Name parameter. An attacker can exploit this remotely and potentially manipulate other parameters. The exploit is publicly known, increasing the risk of attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share