Cross-Site Scripting Vulnerability in SourceCodester Image Compressor Tool
CVE-2025-1169

5.1MEDIUM

Key Information:

Vendor
CVE Published:
11 February 2025

Summary

A cross-site scripting (XSS) vulnerability has been discovered in SourceCodester's Image Compressor Tool 1.0, specifically affecting the file /image-compressor/compressor.php. An attacker can exploit this vulnerability by manipulating the 'image' argument, potentially leading to unauthorized execution of scripts in the context of the affected user’s browser. This vulnerability can be initiated remotely, posing a significant risk to users by exposing them to malicious scripts. The issue has been publicly disclosed, highlighting the urgent need for remediation to protect sensitive data and maintain system integrity.

Affected Version(s)

Image Compressor Tool 1.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

xcode0x (VulDB User)
.