PT-2025-23932 · Unknown · Code-Projects Traffic Offense Reporting System

Ds_Leo

·

Published

2025-06-05

·

Updated

2025-11-13

·

CVE-2025-5661

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions code-projects Traffic Offense Reporting System version 1.0
Description A problematic issue was found in the code-projects Traffic Offense Reporting System, affecting the /save-settings.php file of the Setting Handler component. The manipulation of the site name argument leads to cross-site scripting. This issue can be initiated remotely.
Recommendations For code-projects Traffic Offense Reporting System version 1.0, consider restricting the use of the site name parameter in the affected Setting Handler component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-5661

Affected Products

Code-Projects Traffic Offense Reporting System