Vulnerability Description
A vulnerability was found in needyamin Library Card System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file signup.php of the component Registration Page. The manipulation of the argument firstname/lastname/email/borrow/user_address leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Needyamin | Library Card System | 1.0 |
Related Weaknesses (CWE)
References
- https://vuldb.com/?ctiid.294001Permissions RequiredVDB Entry
- https://vuldb.com/?id.294001Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.485558Third Party AdvisoryVDB Entry
- https://www.websecurityinsights.my.id/2025/01/library-card-system-stored-cross-sExploitThird Party Advisory
FAQ
What is CVE-2025-0844?
CVE-2025-0844 is a vulnerability with a CVSS score of 4.3 (MEDIUM). A vulnerability was found in needyamin Library Card System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file signup.php of the component ...
How severe is CVE-2025-0844?
CVE-2025-0844 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-0844?
Check the references section above for vendor advisories and patch information. Affected products include: Needyamin Library Card System.