PT-2025-31464 · Unknown · Intern Membership Management System
Xuanyuesanshi
·
Publicado
2025-07-31
·
Atualizado
2025-07-31
·
CVE-2025-8340
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Intern Membership Management System version 1.0
Description
A flaw exists in the Error Message Handler component of the software, specifically within the
fill details.php file. Manipulation of the email argument can lead to cross-site scripting (XSS). This issue can be exploited remotely. The exploit for this issue has been publicly disclosed.Recommendations
As a temporary workaround, consider sanitizing the
email input to prevent the injection of malicious scripts.
Restrict access to the fill details.php file to minimize the risk of exploitation.Exploit
Correção
Code Injection
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Intern Membership Management System