PT-2025-36539 · Sourcecodester · Simple To-Do List System

111Ctx

·

Published

2025-09-09

·

Updated

2025-09-09

·

CVE-2025-10117

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: SourceCodester Simple To-Do List System version 1.0
Description: A weakness exists in SourceCodester Simple To-Do List System that allows for cross site scripting. The issue is located in the /fetch tasks.php file, within the Add New Task component, and involves manipulation of input. Specifically, providing the input <script>alert('XSS')</script> can trigger the vulnerability. The exploit has been made publicly available and could be exploited remotely.
Recommendations: As a temporary workaround, consider restricting or disabling the Add New Task component until a fix is available. Sanitize all user-supplied input before using it in the /fetch tasks.php file.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-10117

Affected Products

Simple To-Do List System