Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-19522 | Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to execute JavaScript code by sending a POST request through the password and confirm_password parameters in /register.php. |
Mon, 07 Jul 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Code-projects
Code-projects daily Expense Manager |
|
| CPEs | cpe:2.3:a:code-projects:daily_expense_manager:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Code-projects
Code-projects daily Expense Manager |
|
| Metrics |
cvssV3_1
|
Mon, 30 Jun 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 30 Jun 2025 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to execute JavaScript code by sending a POST request through the password and confirm_password parameters in /register.php. | |
| Title | Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-06-30T17:38:04.889Z
Reserved: 2025-04-16T08:38:23.941Z
Link: CVE-2025-40734
Updated: 2025-06-30T17:38:00.118Z
Status : Analyzed
Published: 2025-06-30T09:15:25.947
Modified: 2025-07-07T18:17:48.017
Link: CVE-2025-40734
No data.
OpenCVE Enrichment
No data.
EUVD