CVE-2025-0464

A vulnerability was found in SourceCodester Task Reminder System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Maintenance Section. The manipulation of the argument System Name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
References
Link Resource
https://vuldb.com/?ctiid.291481 Permissions Required VDB Entry
https://vuldb.com/?id.291481 Third Party Advisory VDB Entry
https://vuldb.com/?submit.474280 Exploit Third Party Advisory VDB Entry
https://www.sourcecodester.com/ Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:oretnom23:task_reminder_system:1.0:*:*:*:*:*:*:*

History

11 Feb 2025, 14:59

Type Values Removed Values Added
References () https://vuldb.com/?ctiid.291481 - () https://vuldb.com/?ctiid.291481 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.291481 - () https://vuldb.com/?id.291481 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.474280 - () https://vuldb.com/?submit.474280 - Exploit, Third Party Advisory, VDB Entry
References () https://www.sourcecodester.com/ - () https://www.sourcecodester.com/ - Product
First Time Oretnom23
Oretnom23 task Reminder System
Summary
  • (es) Se encontró una vulnerabilidad en SourceCodester Task Reminder System 1.0. Se la ha declarado problemática. Esta vulnerabilidad afecta a una funcionalidad desconocida del componente Maintenance Section. La manipulación del argumento System Name conduce a Cross Site Scripting. El ataque se puede lanzar de forma remota. El exploit se ha revelado al público y puede utilizarse.
CPE cpe:2.3:a:oretnom23:task_reminder_system:1.0:*:*:*:*:*:*:*

14 Jan 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-14 17:15

Updated : 2025-02-11 14:59


NVD link : CVE-2025-0464

Mitre link : CVE-2025-0464

CVE.ORG link : CVE-2025-0464


JSON object : View

Products Affected

oretnom23

  • task_reminder_system
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')