Cross-Site Scripting Vulnerability in Dokuzsoft E-Commerce Web Design Product
CVE-2025-8411

7.1HIGH

Key Information:

Vendor
CVE Published:
17 September 2025

What is CVE-2025-8411?

A Cross-Site Scripting (XSS) vulnerability exists in Dokuzsoft Technology's E-Commerce Web Design Product, allowing attackers to exploit improper neutralization of input during web page generation. This vulnerability enables an attacker to inject malicious scripts through HTTP headers, potentially compromising user data and impacting the integrity of web pages. It is advisable for users to upgrade to the latest product version to mitigate associated risks.

Affected Version(s)

E-Commerce Web Design Product 0 < 11.08.2025

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Cetin Binici
.
CVE-2025-8411 : Cross-Site Scripting Vulnerability in Dokuzsoft E-Commerce Web Design Product