PT-2025-31464 · Unknown · Intern Membership Management System

Xuanyuesanshi

·

Published

2025-07-31

·

Updated

2025-07-31

·

CVE-2025-8340

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Intern Membership Management System version 1.0
Description A flaw exists in the Error Message Handler component of the software, specifically within the fill details.php file. Manipulation of the email argument can lead to cross-site scripting (XSS). This issue can be exploited remotely. The exploit for this issue has been publicly disclosed.
Recommendations As a temporary workaround, consider sanitizing the email input to prevent the injection of malicious scripts. Restrict access to the fill details.php file to minimize the risk of exploitation.

Exploit

Fix

Code Injection

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-8340

Affected Products

Intern Membership Management System