Reflected XSS Vulnerability in PuneethReddyHC Online Shopping System
CVE-2025-51971

5.4MEDIUM

Key Information:

Vendor
CVE Published:
28 August 2025

What is CVE-2025-51971?

A vulnerability exists in the PuneethReddyHC Online Shopping System Advanced 1.0, specifically in the register.php file. This flaw allows unsanitized user input from the 'f_name' parameter to be reflected in the server's response. Without proper HTML encoding or output escaping, this vulnerability permits remote attackers to execute arbitrary JavaScript code within the context of the user's browser, leading to potential data theft or unauthorized actions.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.