CVE-2025-60302

MEDIUM

code-projects Client Details System 1.0 - XSS

Title source: llm
STIX 2.1

Description

code-projects Client Details System 1.0 is vulnerable to Cross Site Scripting (XSS). When adding customer information, the client details system fills in malicious JavaScript code in the username field.

References (2)

Core 2

Scores

CVSS v3 6.1
EPSS 0.0003
EPSS Percentile 10.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
fabian/client_details_system 1.0
Published Oct 09, 2025
Tracked Since Feb 18, 2026