CVE-2025-14538

LOW

yangshare warehouseManager 1.1.0 - XSS

Title source: llm

Description

A security vulnerability has been detected in yangshare warehouseManager 仓库管理系统 1.1.0. This affects the function addCustomer of the file CustomerManageHandler.java. Such manipulation of the argument Name leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

Exploits (1)

Scores

CVSS v3 3.5
EPSS 0.0005
EPSS Percentile 16.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-79 CWE-94
Status published
Products (1)
yangshare/warehouseManager 仓库管理系统 1.1.0
Published Dec 11, 2025
Tracked Since Feb 18, 2026