A vulnerability classified as problematic has been found in code-projects Wazifa System 1.0. Affected is the function searchuser of the file /search_resualts.php. The manipulation of the argument firstname/lastname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. There is a typo in the affected file name.
References
| Link | Resource |
|---|---|
| https://code-projects.org/ | Product |
| https://github.com/nanguawuming/CVE2/blob/main/cve2.pdf | Exploit Third Party Advisory |
| https://vuldb.com/?ctiid.295146 | Permissions Required VDB Entry |
| https://vuldb.com/?id.295146 | VDB Entry |
| https://vuldb.com/?submit.497356 | VDB Entry |
Configurations
History
No history.
Information
Published : 2025-02-12 17:15
Updated : 2025-02-19 19:04
NVD link : CVE-2025-1209
Mitre link : CVE-2025-1209
CVE.ORG link : CVE-2025-1209
JSON object : View
Products Affected
anisha
- wazifa_system
