VulnerabilityAnalyzed
CVE-2025-61087
SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the Customer Name field under Customer Management Section.
MEDIUM 6.1EPSS 0.24%
Does this matter?
Lower severity and a low EPSS score (0.24%). Track it; it rarely justifies an emergency change on its own.
Description
SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the Customer Name field under Customer Management Section.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.24% probability · 15th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- mayurik/pet grooming management software
- Source
- cve@mitre.org
References
- https://github.com/sanin-s1r3n/CVE-Research/blob/main/CVE-2025-61087Exploit, Third Party Advisory
- https://www.linkedin.com/in/shuvo-ahmed-sanin/Not Applicable
- https://github.com/sanin-s1r3n/CVE-Research/blob/main/CVE-2025-61087Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.