Cross Site Scripting Vulnerability in SalesERP by Bdtask
CVE-2025-13178
Key Information:
Badges
What is CVE-2025-13178?
A vulnerability has been identified in Bdtask's SalesERP, affecting versions up to 20250728. This flaw resides within the User Profile Handler, specifically the /edit_profile functionality, which improperly handles user input for first_name and last_name fields. This deficiency allows an attacker to execute cross site scripting (XSS) attacks remotely, potentially compromising user data and application integrity. Despite efforts to alert the vendor about this issue, no response has been recorded, and the exploit has been publicly disclosed, escalating the urgency for affected users to implement protective measures.
Affected Version(s)
SalesERP 20250728
SalesERP 20250728
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
