CVE-2025-3692
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2025-3692 is a recently identified vulnerability affecting the SourceCodester Online Eyewear Shop 1.0. This issue poses a significant risk, as it allows for cross-site scripting (XSS) attacks. The vulnerability is located within an unspecified functionality of the file /oews/classes/Master.php, specifically the 'save_product' feature. An attacker can exploit this flaw remotely by manipulating the input, leading to the injection of malicious scripts. The exploit for this vulnerability has been made public, increasing the threat potential for organizations using the affected software.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.