Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-19523 | Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to execute JavaScript code by sending a POST request through the username parameter in /login.php. |
Mon, 07 Jul 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Code-projects
Code-projects daily Expense Manager |
|
| CPEs | cpe:2.3:a:code-projects:daily_expense_manager:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Code-projects
Code-projects daily Expense Manager |
|
| Metrics |
cvssV3_1
|
Mon, 30 Jun 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 30 Jun 2025 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to execute JavaScript code by sending a POST request through the username parameter in /login.php. | |
| Title | Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-06-30T17:42:10.681Z
Reserved: 2025-04-16T08:38:23.941Z
Link: CVE-2025-40733
Updated: 2025-06-30T17:41:58.806Z
Status : Analyzed
Published: 2025-06-30T09:15:25.760
Modified: 2025-07-07T18:18:08.400
Link: CVE-2025-40733
No data.
OpenCVE Enrichment
No data.
EUVD