216.73.217.22

CVE-2025-14201

· Published 07/12/2025 18:16 · Modified 12/12/2025 12:38

Labels: CVE-2025-14201 2025-12-07CVE-2025-14201CWE-79[email protected]

Essential information

Published
07/12/2025 18:16
Modified
12/12/2025 12:38
Author
Creator
CVSS
4.8 MEDIUM (v3) 4.8 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability was found in alokjaiswal Hotel-Management-services-using-MYSQL-and-php up to 5f8b60a7aa6c06a5632de569d4e3f6a8cd82f76f. Affected by this vulnerability is an unknown functionality of the file /dishsub.php. The manipulation of the argument item.name results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The vendor was contacted early about this disclosure but did not respond in any way.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
alokjaiswal / hotel-management-services-using-mysql-and-php cpe:2.3:a:alokjaiswal:hotel-management-services-using-mysql-and-php:*:*:*:*:*:*:*:*

References