CVE 5.1 MEDIUM

Iqbolshoh php-business-website contact.php cross site scripting_CVE-2025-12224

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P

Description

A flaw has been found in Iqbolshoh php-business-website up to 10677743a8dfc281f85291a27cf63a0bce043c24. This vulnerability affects unknown code of the file admin/contact.php. This manipulation of the argument twitter causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.

Basic Information

ID CVE-2025-12224
Source VulDB
Published Oct 27, 2025 at 04:32

Affected Product

Vendor Iqbolshoh
Product php-business-website
Version 10677743a8dfc281f85291a27cf63a0bce043c24
Affected Versions Iqbolshoh php-business-website 10677743a8dfc281f85291a27cf63a0bce043c24

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.