Cross Site Scripting Vulnerability in itsourcecode Online Petshop Management System
CVE-2025-10631
Key Information:
- Vendor
Itsourcecode
- Vendor
- CVE Published:
- 18 September 2025
Badges
What is CVE-2025-10631?
A cross site scripting vulnerability has been identified in the itsourcecode Online Petshop Management System version 1.0. The issue resides in the addcnp.php file, specifically within an unknown function tied to the Available Products Page. By manipulating the name or description argument, attackers can inject malicious scripts, potentially leading to unauthorized actions. The vulnerability allows for remote exploitation, and proof-of-concept exploits are publicly available, increasing the risks for users and administrators.
Affected Version(s)
Online Petshop Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
