Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 10 Oct 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Configuroweb simple Web Inventory System
|
|
| CPEs | cpe:2.3:a:configuroweb:simple_web_inventory_system:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Configuroweb simple Web Inventory System
|
Thu, 09 Oct 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Configuroweb
Configuroweb sistema Web De Inventario |
|
| Vendors & Products |
Configuroweb
Configuroweb sistema Web De Inventario |
Wed, 08 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Wed, 08 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Configuroweb Sistema Web de Inventario 1.0 is vulnerable to a Stored Cross-Site Scripting (XSS) due to the lack of input sanitization on the product name parameter (Nombre:Producto) allowing an authenticated attacker to inject malicious payloads and execute arbitrary JavaScript. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-08T13:50:08.433Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-60314
Updated: 2025-10-08T13:49:34.568Z
Status : Analyzed
Published: 2025-10-08T14:15:45.373
Modified: 2025-10-10T16:17:36.040
Link: CVE-2025-60314
No data.
OpenCVE Enrichment
Updated: 2025-10-09T12:55:11Z