VulnerabilityModified
CVE-2025-14991
A weakness has been identified in Campcodes Complete Online Beauty Parlor Management System 1.0.
LOW 1.9EPSS 0.23%
Does this matter?
Lower severity and a low EPSS score (0.23%). Track it; it rarely justifies an emergency change on its own.
Description
A weakness has been identified in Campcodes Complete Online Beauty Parlor Management System 1.0. The affected element is an unknown function of the file /admin/bwdates-reports-details.php. Executing a manipulation of the argument fromdate can lead to cross site scripting. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
- CVSS 4.0
- 1.9 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.23% probability · 14th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79, CWE-94
- Affected
- campcodes/complete online beauty parlor management system
- Source
- cna@vuldb.com
References
- https://github.com/funnnxxx/my-cve/issues/1Exploit, Issue Tracking
- https://vuldb.com/?ctiid.337685Permissions Required, VDB Entry
- https://vuldb.com/?id.337685Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.718458Third Party Advisory, VDB Entry
- https://www.campcodes.com/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.