PT-2025-6851 · Unknown · Code-Projects Wazifa System

Exvtaw5N

·

Published

2025-02-12

·

Updated

2025-02-13

·

CVE-2025-1209

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions code-projects Wazifa System version 1.0
Description A problematic issue has been found in the searchuser function of the /search resualts.php file. The manipulation of the firstname/lastname argument leads to cross site scripting. It is possible to launch the attack remotely. There is a typo in the affected file name.
Recommendations For code-projects Wazifa System version 1.0, consider disabling the searchuser function in the /search resualts.php file as a temporary workaround until a patch is available. Restrict access to the /search resualts.php file to minimize the risk of exploitation. Avoid using the firstname and lastname arguments in the affected function until the issue is resolved.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-1209

Affected Products

Code-Projects Wazifa System