Cross-Site Scripting in yangshare warehouseManager by yangshare
CVE-2025-14538
Key Information:
- Vendor
Yangshare
- Status
- Vendor
- CVE Published:
- 11 December 2025
Badges
What is CVE-2025-14538?
A security vulnerability in yangshare warehouseManager version 1.1.0 allows for cross-site scripting (XSS) through the addCustomer function in CustomerManageHandler.java. Attackers can exploit this vulnerability by manipulating the 'Name' argument, which can result in remote attacks. This disclosed flaw poses significant security risks as it permits the execution of scripts in the context of an affected user's session, potentially leading to data theft or unauthorized actions.
Affected Version(s)
warehouseManager 仓库管理系统 1.1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
