CVE-2025-52203

HIGH

DevaslanPHP project-management 1.2.4 - Authenticated Stored Cross-Site Scripting in Ticket Name Field

Title source: llm
STIX 2.1

Description

A stored cross-site scripting (XSS) vulnerability exists in DevaslanPHP project-management v1.2.4. The vulnerability resides in the Ticket Name field, which fails to properly sanitize user-supplied input. An authenticated attacker can inject malicious JavaScript payloads into this field, which are subsequently stored in the database. When a legitimate user logs in and is redirected to the Dashboard panel "automatically upon authentication the malicious script executes in the user's browser context.

Scores

CVSS v3 7.6
EPSS 0.0031
EPSS Percentile 22.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
devaslanphp/project_management 1.2.4
Published Jul 31, 2025
Tracked Since Feb 18, 2026