Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Ticket Booking System v1.0 allows an attacker to execute arbitrary code into the Full Name and Address fields during user registration or profile editing.
Metrics
Affected Vendors & Products
References
History
Wed, 30 Apr 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Codeastro
Codeastro bus Ticket Booking System |
|
CPEs | cpe:2.3:a:codeastro:bus_ticket_booking_system:1.0:*:*:*:*:*:*:* | |
Vendors & Products |
Codeastro
Codeastro bus Ticket Booking System |
Mon, 28 Apr 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
cvssV3_1
|
Mon, 28 Apr 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Ticket Booking System v1.0 allows an attacker to execute arbitrary code into the Full Name and Address fields during user registration or profile editing. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-04-28T00:00:00.000Z
Updated: 2025-04-28T17:36:45.256Z
Reserved: 2025-02-07T00:00:00.000Z
Link: CVE-2025-25776

Updated: 2025-04-28T17:36:38.731Z

Status : Analyzed
Published: 2025-04-28T15:15:45.587
Modified: 2025-04-30T18:58:22.110
Link: CVE-2025-25776

No data.