PT-2025-6851 · Unknown · Code-Projects Wazifa System

·

CVE-2025-1209

·

Published

2025-02-12

·

Updated

2025-02-13

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions code-projects Wazifa System version 1.0
Description A problematic issue has been found in the searchuser function of the /search resualts.php file. The manipulation of the firstname/lastname argument leads to cross site scripting. It is possible to launch the attack remotely. There is a typo in the affected file name.
Recommendations For code-projects Wazifa System version 1.0, consider disabling the searchuser function in the /search resualts.php file as a temporary workaround until a patch is available. Restrict access to the /search resualts.php file to minimize the risk of exploitation. Avoid using the firstname and lastname arguments in the affected function until the issue is resolved.

Exploit

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-1209

Affected Products

Code-Projects Wazifa System