CVE-2025-25776
CVSS 3.1 Score 5 of 10 (medium)
Details
Summary
CVE-2025-25776 refers to a Cross-Site Scripting (XSS) vulnerability identified in the Codeastro Bus Ticket Booking System v1.0. This issue affects the User Registration and User Profile features. An attacker can exploit this weakness by injecting malicious code into the Full Name and Address fields during user registration or profile editing. Successful exploitation allows the attacker to execute arbitrary code on unsuspecting users' browsers. This vulnerability poses a significant risk, as it can lead to data theft, session hijacking, and other malicious activities. Users are strongly advised to update to the latest version of the Codeastro Bus Ticket Booking System to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.