A vulnerability was identified in itsourcecode Online Petshop Management System 1.0. Impacted is an unknown function of the file addcnp.php of the component Available Products Page. The manipulation of the argument name/description leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
History

Mon, 22 Sep 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Facebook-riares
Facebook-riares online Petshop Management System
CPEs cpe:2.3:a:facebook-riares:online_petshop_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Facebook-riares
Facebook-riares online Petshop Management System

Thu, 18 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 18 Sep 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Itsourcecode
Itsourcecode online Petshop Management System
Vendors & Products Itsourcecode
Itsourcecode online Petshop Management System

Thu, 18 Sep 2025 00:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in itsourcecode Online Petshop Management System 1.0. Impacted is an unknown function of the file addcnp.php of the component Available Products Page. The manipulation of the argument name/description leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
Title itsourcecode Online Petshop Management System Available Products addcnp.php cross site scripting
Weaknesses CWE-79
CWE-94
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-09-18T13:25:26.232Z

Reserved: 2025-09-17T12:12:37.950Z

Link: CVE-2025-10631

cve-icon Vulnrichment

Updated: 2025-09-18T13:25:17.670Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-18T01:15:36.193

Modified: 2025-09-20T02:37:04.060

Link: CVE-2025-10631

cve-icon Redhat

No data.