Cross Site Scripting Vulnerability in Laundry Laundry System by Unknown Vendor
CVE-2025-5797
Key Information:
- Vendor
Code-projects
- Status
- Vendor
- CVE Published:
- 6 June 2025
Badges
What is CVE-2025-5797?
A cross site scripting vulnerability has been identified within Laundry Laundry System 1.0, specifically affecting the handling of the /data/insert_type.php file. This issue arises from inadequate input validation, which allows an attacker to manipulate the 'Type' argument. The flaw could facilitate remote exploitation, enabling attackers to execute malicious scripts within users' browsers, compromising sensitive information and user session integrity. Public disclosure of this vulnerability raises concerns about its misuse by malicious actors.
Affected Version(s)
Laundry System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved