XSS Vulnerability in SourceCodester Pet Grooming Management Software
CVE-2025-60318

6.1MEDIUM

Key Information:

Vendor
CVE Published:
8 October 2025

What is CVE-2025-60318?

The Pet Grooming Management Software version 1.0 by SourceCodester contains a Cross Site Scripting (XSS) vulnerability within the admin profile management section. Specifically, the 'fname' (First Name) and 'lname' (Last Name) fields do not properly sanitize user input, allowing an attacker to inject malicious scripts. This manipulation can lead to various security risks, including the theft of session cookies, unauthorized access to user accounts, and overall compromise of the application’s integrity.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-60318 : XSS Vulnerability in SourceCodester Pet Grooming Management Software