PT-2025-49419 · Code Projects · Chamber Of Commerce Membership Management System

H1Mm

·

Published

2025-12-07

·

Updated

2025-12-08

·

CVE-2025-14205

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions code-projects Chamber of Commerce Membership Management System version 1.0
Description A flaw exists in the Your Info Handler component of the software, specifically within the /membership profile.php file. Manipulation of the Full Name, Address, City, or State arguments can lead to cross site scripting. This issue is remotely exploitable, and details about the exploit are publicly available.
Recommendations Apply a fix for version 1.0 to address the cross site scripting issue. As a temporary workaround, consider sanitizing the Full Name, Address, City, and State input parameters to prevent malicious script injection.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-14205

Affected Products

Chamber Of Commerce Membership Management System