VulnerabilityAnalyzed
CVE-2025-15583
A weakness has been identified in detronetdip E-commerce 1.0.0.
LOW 2.0EPSS 0.24%
Does this matter?
Lower severity and a low EPSS score (0.24%). Track it; it rarely justifies an emergency change on its own.
Description
A weakness has been identified in detronetdip E-commerce 1.0.0. This affects the function get_safe_value of the file utility/function.php. Executing a manipulation can lead to cross site scripting. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
- CVSS 4.0
- 2.0 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.24% probability · 15th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79, CWE-94
- Affected
- detronetdip/e-commerce
- Source
- cna@vuldb.com
References
- https://github.com/Nixon-H/PHP-Stored-XSS-Bypass-Real-EscapeExploit, Mitigation, Third Party Advisory
- https://github.com/detronetdip/E-commerce/Product
- https://github.com/detronetdip/E-commerce/issues/23Exploit, Issue Tracking, Vendor Advisory
- https://vuldb.com/?ctiid.346487Permissions Required, VDB Entry
- https://vuldb.com/?id.346487Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.754033Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.