Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-26062 | A reflected Cross-Site Scripting (XSS) vulnerability exists in register.php of PuneethReddyHC Online Shopping System Advanced 1.0. Unsanitized user input in the f_name parameter is reflected in the server response without proper HTML encoding or output escaping. This allows remote attackers to inject arbitrary JavaScript code. |
Tue, 09 Sep 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:puneethreddyhc:online_shopping_system_advanced:1.0:*:*:*:*:*:*:* |
Thu, 28 Aug 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Puneethreddyhc
Puneethreddyhc online Shopping System Advanced |
|
| Vendors & Products |
Puneethreddyhc
Puneethreddyhc online Shopping System Advanced |
Thu, 28 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Thu, 28 Aug 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A reflected Cross-Site Scripting (XSS) vulnerability exists in register.php of PuneethReddyHC Online Shopping System Advanced 1.0. Unsanitized user input in the f_name parameter is reflected in the server response without proper HTML encoding or output escaping. This allows remote attackers to inject arbitrary JavaScript code. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-08-28T14:26:39.615Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-51971
Updated: 2025-08-28T14:26:35.845Z
Status : Analyzed
Published: 2025-08-28T14:15:49.717
Modified: 2025-09-09T18:42:47.563
Link: CVE-2025-51971
No data.
OpenCVE Enrichment
Updated: 2025-08-28T21:21:33Z
EUVD