CVE-2025-25776

CVSS 3.1 Score 5 of 10 (medium)

Details

Published Apr 28, 2025
Updated: Apr 30, 2025
CWE ID 79

Summary

CVE-2025-25776 refers to a Cross-Site Scripting (XSS) vulnerability identified in the Codeastro Bus Ticket Booking System v1.0. This issue affects the User Registration and User Profile features. An attacker can exploit this weakness by injecting malicious code into the Full Name and Address fields during user registration or profile editing. Successful exploitation allows the attacker to execute arbitrary code on unsuspecting users' browsers. This vulnerability poses a significant risk, as it can lead to data theft, session hijacking, and other malicious activities. Users are strongly advised to update to the latest version of the Codeastro Bus Ticket Booking System to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share