Cross-Site Scripting Vulnerability in SourceCodester Image Compressor Tool
CVE-2025-1169
Key Information:
- Vendor
Sourcecodester
- Status
- Vendor
- CVE Published:
- 11 February 2025
What is CVE-2025-1169?
A cross-site scripting (XSS) vulnerability has been discovered in SourceCodester's Image Compressor Tool 1.0, specifically affecting the file /image-compressor/compressor.php. An attacker can exploit this vulnerability by manipulating the 'image' argument, potentially leading to unauthorized execution of scripts in the context of the affected user’s browser. This vulnerability can be initiated remotely, posing a significant risk to users by exposing them to malicious scripts. The issue has been publicly disclosed, highlighting the urgent need for remediation to protect sensitive data and maintain system integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Image Compressor Tool 1.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
