Cross-Site Scripting Vulnerability in SourceCodester Image Compressor Tool
CVE-2025-1169
5.1MEDIUM
Key Information:
- Vendor
- Sourcecodester
- Status
- Vendor
- CVE Published:
- 11 February 2025
Summary
A cross-site scripting (XSS) vulnerability has been discovered in SourceCodester's Image Compressor Tool 1.0, specifically affecting the file /image-compressor/compressor.php. An attacker can exploit this vulnerability by manipulating the 'image' argument, potentially leading to unauthorized execution of scripts in the context of the affected user’s browser. This vulnerability can be initiated remotely, posing a significant risk to users by exposing them to malicious scripts. The issue has been publicly disclosed, highlighting the urgent need for remediation to protect sensitive data and maintain system integrity.
Affected Version(s)
Image Compressor Tool 1.0
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
xcode0x (VulDB User)