Stored Cross-Site Scripting Vulnerability in DevaslanPHP Project Management
CVE-2025-52203

7.6HIGH

Key Information:

Vendor
CVE Published:
31 July 2025

What is CVE-2025-52203?

A stored cross-site scripting (XSS) vulnerability in the DevaslanPHP Project Management tool allows an attacker to inject malicious JavaScript into the Ticket Name field, which does not properly sanitize input. This injected script is then stored in the database, posing a risk when a legitimate user logs into the application. Upon successful authentication, the user is redirected to the Dashboard panel, where the malicious code executes within their browser context, potentially compromising user data and security.

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.