PT-2025-31453 · Unknown · Simple Car Rental System
Ic0Rner
·
Published
2025-07-30
·
Updated
2025-07-31
·
CVE-2025-8337
Ic0Rner
·
Published
2025-07-30
·
Updated
2025-07-31
·
CVE-2025-8337
3.3
Low
Base vector | Vector | AV:N/AC:L/Au:M/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Simple Car Rental System version 1.0
Description:
A problematic issue has been found in the processing of the `/admin/add vehicles.php` file. Manipulation of the `car name` argument can lead to cross site scripting. The attack can be initiated remotely, and the exploit has been publicly disclosed.
Recommendations:
As a mitigation, sanitize the `car name` input to prevent the injection of malicious scripts.
Exploit
Fix
XSS
Code Injection