CVE-2025-14538
LOWyangshare warehouseManager 1.1.0 - XSS
Title source: llmDescription
A security vulnerability has been detected in yangshare warehouseManager 仓库管理系统 1.1.0. This affects the function addCustomer of the file CustomerManageHandler.java. Such manipulation of the argument Name leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Exploits (1)
gitee
1,059 stars
by yangshare · javawriteup
https://gitee.com/yangshare/warehouseManager/issues/ID9NAU
Scores
CVSS v3
3.5
EPSS
0.0005
EPSS Percentile
16.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Details
CWE
CWE-79
CWE-94
Status
published
Products (1)
yangshare/warehouseManager 仓库管理系统
1.1.0
Published
Dec 11, 2025
Tracked Since
Feb 18, 2026