CVE-2025-3692

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Apr 16, 2025
Updated: Apr 29, 2025
CWE ID 94
CWE ID 79

Summary

CVE-2025-3692 is a recently identified vulnerability affecting the SourceCodester Online Eyewear Shop 1.0. This issue poses a significant risk, as it allows for cross-site scripting (XSS) attacks. The vulnerability is located within an unspecified functionality of the file /oews/classes/Master.php, specifically the 'save_product' feature. An attacker can exploit this flaw remotely by manipulating the input, leading to the injection of malicious scripts. The exploit for this vulnerability has been made public, increasing the threat potential for organizations using the affected software.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share