Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 04 Feb 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:bhabishya-123:e-commerce:1.0:*:*:*:*:*:*:* |
Wed, 19 Nov 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bhabishya-123
Bhabishya-123 e-commerce |
|
| Vendors & Products |
Bhabishya-123
Bhabishya-123 e-commerce |
Tue, 18 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Tue, 18 Nov 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A DOM-based cross-site scripting vulnerability exists in electic-shop v1.0 (Bhabishya-123/E-commerce). The site's client-side JavaScript reads attacker-controlled input (for example, values derived from the URL or page fragment) and inserts it into the DOM via unsafe sinks (innerHTML/insertAdjacentHTML/document.write) without proper sanitization or context-aware encoding. An attacker can craft a malicious URL that, when opened by a victim, causes arbitrary JavaScript to execute in the victim's browser under the electic-shop origin. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-18T15:00:49.066Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63883
Updated: 2025-11-18T15:00:45.347Z
Status : Analyzed
Published: 2025-11-18T15:16:36.097
Modified: 2026-02-04T20:42:48.477
Link: CVE-2025-63883
No data.
OpenCVE Enrichment
Updated: 2025-11-19T10:47:48Z