XSS Vulnerability in Water Management System by Sanin
CVE-2025-63446

6.1MEDIUM

Key Information:

Vendor

Sanin

Vendor
CVE Published:
3 November 2025

What is CVE-2025-63446?

The Water Management System v1.0 is susceptible to a Cross Site Scripting (XSS) vulnerability located in the /add_vendor.php file. Attackers can exploit this flaw to inject malicious scripts, potentially compromising user data and application integrity. It is crucial for users of the Water Management System to assess their vulnerabilities and implement appropriate security measures to safeguard against any potential exploitation.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-63446 : XSS Vulnerability in Water Management System by Sanin