CVE-2025-25776

Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Ticket Booking System v1.0 allows an attacker to execute arbitrary code into the Full Name and Address fields during user registration or profile editing.
Configurations

Configuration 1 (hide)

cpe:2.3:a:codeastro:bus_ticket_booking_system:1.0:*:*:*:*:*:*:*

History

30 Apr 2025, 18:58

Type Values Removed Values Added
References () https://codeastro.com/bus-ticket-booking-system-in-php-codeigniter-with-source-code/ - () https://codeastro.com/bus-ticket-booking-system-in-php-codeigniter-with-source-code/ - Product
References () https://github.com/arunmodi/Vulnerability-Research/tree/main/CVE-2025-25776 - () https://github.com/arunmodi/Vulnerability-Research/tree/main/CVE-2025-25776 - Exploit, Third Party Advisory
CPE cpe:2.3:a:codeastro:bus_ticket_booking_system:1.0:*:*:*:*:*:*:*
First Time Codeastro
Codeastro bus Ticket Booking System

29 Apr 2025, 13:52

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de Cross-Site Scripting (XSS) en las funciones de registro de usuario y perfil de usuario de Codeastro Bus Ticket Booking System v1.0 que permite a un atacante ejecutar código arbitrario en los campos de nombre completo y dirección durante el registro del usuario o la edición del perfil.

28 Apr 2025, 18:15

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.0

28 Apr 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-28 15:15

Updated : 2025-04-30 18:58


NVD link : CVE-2025-25776

Mitre link : CVE-2025-25776

CVE.ORG link : CVE-2025-25776


JSON object : View

Products Affected

codeastro

  • bus_ticket_booking_system
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')