PT-2025-35837 · Code Projects · Responsive Blog Site

111Ctx

·

Published

2025-09-03

·

Updated

2025-09-04

·

CVE-2025-9929

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions code-projects Responsive Blog Site version 1.0
Description A weakness exists in code-projects Responsive Blog Site 1.0, affecting an unknown function within the blogs view.php file. Manipulation of the product code, gen name, product name, or supplier argument can lead to cross site scripting. This issue is potentially exploitable remotely, and an exploit has been publicly released.
Recommendations As a temporary workaround, consider restricting or sanitizing the product code, gen name, product name, and supplier arguments to prevent manipulation. Disable or restrict access to the blogs view.php file until a fix is available.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-9929

Affected Products

Responsive Blog Site