CNNVD-202509-1465 Information

CNNVD ID

CNNVD-202509-1465

CVE-2025-10117

  • CNNVD Published: 2025-09-09

Description (Chinese)

SourceCodester Simple To-Do List System是SourceCodester开源的一个简单待办事项列表系统。 SourceCodester Simple To-Do List System 1.0版本存在代码注入漏洞,该漏洞源于对组件Add New Task中文件/fetch_tasks.php的错误操作导致跨站脚本攻击。

Description (English)

SourceCodester Simple To-Do List System is a simple to-do list system from the SourceCodester. SourceCodester Simple To-Do List System 1.0 has a code infusion loophole, which stems from the error in the document/fetch tasks.php of the component Add New Task resulting in a cross-site script attack.

Hazard Level

Critical

Vulnerability Type

代码注入

Affected Vendor

Sparkle Motion

Published

2025-09-09

Last Modified

2026-02-24

References

https://github.com/chen2496088236/CVE/issues/11 https://vuldb.com/?ctiid.323087 https://vuldb.com/?id.323087 https://vuldb.com/?submit.645597 https://www.sourcecodester.com/

Patch

https://www.sourcecodester.com/

Share on: