PT-2025-39095 · Phpjabbers · Restaurant Menu Maker
Nyxswl
·
Published
2025-09-23
·
Updated
2025-09-23
·
CVE-2025-10827
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PHPJabbers Restaurant Menu Maker versions up to 1.1
Description
A cross-site scripting issue exists in PHPJabbers Restaurant Menu Maker. The issue is related to the
/preview.php file and manipulation of the theme parameter. This manipulation can lead to cross-site scripting, and the attack can be initiated remotely. The exploit has been publicly released.Recommendations
Versions prior to 1.1 should be updated.
Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Restaurant Menu Maker