CVE-2025-60314

Configuroweb Sistema Web de Inventario 1.0 is vulnerable to a Stored Cross-Site Scripting (XSS) due to the lack of input sanitization on the product name parameter (Nombre:Producto) allowing an authenticated attacker to inject malicious payloads and execute arbitrary JavaScript.
Configurations

Configuration 1 (hide)

cpe:2.3:a:configuroweb:simple_web_inventory_system:1.0:*:*:*:*:*:*:*

History

10 Oct 2025, 16:17

Type Values Removed Values Added
First Time Configuroweb
Configuroweb simple Web Inventory System
CPE cpe:2.3:a:configuroweb:simple_web_inventory_system:1.0:*:*:*:*:*:*:*
References () https://configuroweb.com/sistema-web-de-inventario-simple-en-php-mysql/ - () https://configuroweb.com/sistema-web-de-inventario-simple-en-php-mysql/ - Product
References () https://github.com/ChuckBartowski7/Vulnerability-Research/blob/main/CVE-2025-60314/README.md - () https://github.com/ChuckBartowski7/Vulnerability-Research/blob/main/CVE-2025-60314/README.md - Exploit, Third Party Advisory
References () https://github.com/configuroweb/inventariobasico - () https://github.com/configuroweb/inventariobasico - Product

08 Oct 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-08 14:15

Updated : 2025-10-10 16:17


NVD link : CVE-2025-60314

Mitre link : CVE-2025-60314

CVE.ORG link : CVE-2025-60314


JSON object : View

Products Affected

configuroweb

  • simple_web_inventory_system
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')