PT-2025-31464 · Unknown · Intern Membership Management System

Xuanyuesanshi

·

Publicado

2025-07-31

·

Atualizado

2025-07-31

·

CVE-2025-8340

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Intern Membership Management System version 1.0
Description A flaw exists in the Error Message Handler component of the software, specifically within the fill details.php file. Manipulation of the email argument can lead to cross-site scripting (XSS). This issue can be exploited remotely. The exploit for this issue has been publicly disclosed.
Recommendations As a temporary workaround, consider sanitizing the email input to prevent the injection of malicious scripts. Restrict access to the fill details.php file to minimize the risk of exploitation.

Exploit

Correção

Code Injection

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-8340

Produtos afetados

Intern Membership Management System