A security flaw has been discovered in SourceCodester Online Polling System 1.0. The impacted element is an unknown function of the file /manage-profile.php. The manipulation of the argument firstname results in cross site scripting. The attack can be launched remotely. The exploit has been released to the public and may be exploited.
History

Tue, 09 Sep 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Razormist
Razormist online Polling System
CPEs cpe:2.3:a:razormist:online_polling_system:1.0:*:*:*:*:*:*:*
Vendors & Products Razormist
Razormist online Polling System

Mon, 08 Sep 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 08 Sep 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Sourcecodester
Sourcecodester online Polling System
Vendors & Products Sourcecodester
Sourcecodester online Polling System

Mon, 08 Sep 2025 00:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in SourceCodester Online Polling System 1.0. The impacted element is an unknown function of the file /manage-profile.php. The manipulation of the argument firstname results in cross site scripting. The attack can be launched remotely. The exploit has been released to the public and may be exploited.
Title SourceCodester Online Polling System manage-profile.php cross site scripting
Weaknesses CWE-79
CWE-94
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-09-08T00:32:06.129Z

Updated: 2025-09-08T17:01:35.036Z

Reserved: 2025-09-07T11:48:45.410Z

Link: CVE-2025-10075

cve-icon Vulnrichment

Updated: 2025-09-08T17:00:44.492Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-08T01:15:40.280

Modified: 2025-09-09T15:52:25.713

Link: CVE-2025-10075

cve-icon Redhat

No data.