Cross-Site Scripting Vulnerability in Sourcecodester AI-Powered To-Do List App
CVE-2025-63638
6.1MEDIUM
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 7 November 2025
What is CVE-2025-63638?
The Sourcecodester AI-Powered To-Do List App version 1.0 is susceptible to a Cross-Site Scripting (XSS) issue. This vulnerability occurs within the 'Task Title' and 'Description (Optional)' fields during task creation. Attackers can exploit this flaw to inject arbitrary HTML or JavaScript code. When users click the 'Add Task' button, the inserted code executes in their browsers, potentially compromising user data and session security. It is crucial for users and administrators to be aware of this vulnerability and take necessary precautions to mitigate potential threats.
