XSS Vulnerability in City Guide by giSoft Information Technologies
CVE-2025-10612

6.1MEDIUM

Key Information:

Vendor
CVE Published:
21 October 2025

What is CVE-2025-10612?

A security flaw exists in the City Guide application by giSoft Information Technologies, where improper handling of user input during web page generation leads to a reflected Cross-site Scripting (XSS) vulnerability. Attackers can exploit this issue to execute arbitrary scripts in the context of the user's session, potentially compromising sensitive information or redirecting users to malicious websites. It is essential for users of City Guide versions prior to 1.4.45 to apply security updates and implement best practices for web application security to mitigate the risks associated with this vulnerability.

Affected Version(s)

City Guide 0 < 1.4.45

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Barış BAYDUR
.
CVE-2025-10612 : XSS Vulnerability in City Guide by giSoft Information Technologies