Cross-Site Scripting Vulnerability in Code-Projects Intern Membership Management System
CVE-2025-8340
Key Information:
- Vendor
Code-projects
- Vendor
- CVE Published:
- 31 July 2025
Badges
What is CVE-2025-8340?
A security flaw exists in the Code-Projects Intern Membership Management System version 1.0, specifically located in the code handling the fill_details.php file. This vulnerability allows attackers to exploit the argument 'email', leading to potential cross-site scripting (XSS) attacks. Since this issue can be triggered remotely, it poses a significant risk to users. Given that the exploit has been disclosed publicly, it is crucial for users to understand and address this vulnerability promptly to protect their systems and sensitive information.
Affected Version(s)
Intern Membership Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.