Cross-Site Scripting (XSS) vulnerability in Bang Resto v1.0 could allow an attacker to inject malicious JavaScript code into the application's web pages. This vulnerability exists due to insufficient input sanitization or output encoding, allowing attacker-controlled input to be rendered directly in the browser. When exploited, an attacker can steal session cookies, redirect users to malicious sites, perform actions on behalf of the user, or deface the website. This can lead to user data compromise, loss of user trust, and a broader attack surface for more advanced exploitation techniques.
References
| Link | Resource |
|---|---|
| https://github.com/debug-security/CVE/tree/main/CVE-2025-60280 | Exploit Third Party Advisory |
| https://vwrap.live/stored-xss-in-bangresto | Exploit Third Party Advisory |
Configurations
History
31 Oct 2025, 14:48
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/debug-security/CVE/tree/main/CVE-2025-60280 - Exploit, Third Party Advisory | |
| References | () https://vwrap.live/stored-xss-in-bangresto - Exploit, Third Party Advisory | |
| CPE | cpe:2.3:a:hockeycomputindo:bang_resto:1.0:*:*:*:*:*:*:* | |
| First Time |
Hockeycomputindo
Hockeycomputindo bang Resto |
21 Oct 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-21 16:15
Updated : 2025-10-31 14:48
NVD link : CVE-2025-60280
Mitre link : CVE-2025-60280
CVE.ORG link : CVE-2025-60280
JSON object : View
Products Affected
hockeycomputindo
- bang_resto
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
