4.8
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
Description
A security vulnerability has been detected in projectworlds Expense Management System 1.0. Affected is an unknown function of the file /public/admin/expense_categories/create of the component Expense Categories Page. Such manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Basic Information
ID
CVE-2025-12231
Source
VulDB
Published
Oct 27, 2025 at 06:02
Affected Product
Vendor
projectworlds
Product
Expense Management System
Version
1.0
Affected Versions
projectworlds Expense Management System 1.0