CVE-2025-15188: Campcodes Complete Online Beauty Parlor Management System search-invoices.php cross site scripting
A vulnerability was determined in Campcodes Complete Online Beauty Parlor Management System 1.0. This vulnerability affects unknown code of the file /admin/search-invoices.php. Executing a manipulation of the argument searchdata can lead to cross site scripting. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15188?
The severity of CVE-2025-15188 is classified as a cross-site scripting (XSS) vulnerability.
How do I fix CVE-2025-15188?
To fix CVE-2025-15188, sanitize and validate user inputs in the searchdata parameter to prevent XSS attacks.
What software is impacted by CVE-2025-15188?
CVE-2025-15188 affects Campcodes Complete Online Beauty Parlor Management System version 1.0.
What impact does CVE-2025-15188 have?
CVE-2025-15188 allows attackers to execute malicious scripts on users' browsers, potentially compromising user data.
Where in the application is CVE-2025-15188 located?
CVE-2025-15188 is located in the file /admin/search-invoices.php of the affected application.