ZeroHour

CVE-2025-51971

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p19
Published
()
Modified
Description

A reflected Cross-Site Scripting (XSS) vulnerability exists in register.php of PuneethReddyHC Online Shopping System Advanced 1.0. Unsanitized user input in the f_name parameter is reflected in the server response without proper HTML encoding or output escaping. This allows remote attackers to inject arbitrary JavaScript code.

Vendors
puneethreddyhc
Products
online shopping system advanced
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.