PT-2025-43969 · Sui Shang Information Technology · Suishang Enterprise-Level B2B2C Multi-User Mall System

Zre0X1C

·

Published

2025-10-27

·

Updated

2025-10-27

·

CVE-2025-12290

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System version 1.0
Description A cross site scripting issue exists in Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System version 1.0. The issue is related to the manipulation of the keywords argument within the file '/i/359'. This allows for remote execution of the attack. The exploit details have been publicly disclosed, and the vendor was notified but did not respond.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-12290

Affected Products

Suishang Enterprise-Level B2B2C Multi-User Mall System