PT-2025-43968 · Sui Shang Information Technology · Suishang Enterprise-Level B2B2C Multi-User Mall System

Zre0X1C

·

Published

2025-10-27

·

Updated

2025-10-27

·

CVE-2025-12289

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System version 1.0
Description A flaw exists in the system that allows for cross site scripting. Manipulation of the category id argument in the file '/Point/index/activity state/1/category id/1001' can trigger this issue. The attack can be executed remotely. The exploit has been published. The vendor was contacted but did not respond.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-12289

Affected Products

Suishang Enterprise-Level B2B2C Multi-User Mall System