CNNVD-202508-1480 Information

CNNVD ID

CNNVD-202508-1480

CVE-2025-8933

  • CNNVD Published: 2025-08-14

Description (Chinese)

1000 Projects Sales Management System是1000 Projects开源的一个销售管理系统。 1000 Projects Sales Management System 1.0版本存在代码注入漏洞,该漏洞源于文件/superstore/admin/sales.php中参数ssalescat的错误操作导致跨站脚本攻击。

Description (English)

1,000 Projects Sales Management Systems is a sales management system that is an open source of 1,000 Projects. Version 1.0 of 1,000 Projects Sales Management System contains a code-injection loophole resulting from the error of salescat, the parameter in the file/superstore/admin/sales.php, resulting in a cross-site script attack.

Hazard Level

High

Vulnerability Type

代码注入

Affected Vendor

1000 Projects

Published

2025-08-14

Last Modified

2026-02-24

References

https://1000projects.org/ https://github.com/lan041221/cvec/issues/4 https://vuldb.com/?ctiid.319895 https://vuldb.com/?id.319895 https://vuldb.com/?submit.631708

Share on: