Multiple Cross-Site Scripting (XSS) vulnerabilities exist in xmall v1.1 due to improper handling of user-supplied data. User input fields such as username and description are directly rendered into HTML without proper sanitization or encoding, allowing attackers to inject and execute malicious scripts.
References
History

Sat, 29 Nov 2025 03:45:00 +0000

Type Values Removed Values Added
Description Multiple Cross-Site Scripting (XSS) vulnerabilities exist in xmall v1.1 due to improper handling of user-supplied data. User input fields such as username and description are directly rendered into HTML without proper sanitization or encoding, allowing attackers to inject and execute malicious scripts.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-11-29T00:00:00.000Z

Updated: 2025-11-29T03:26:05.636Z

Reserved: 2025-11-18T00:00:00.000Z

Link: CVE-2025-65540

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-29T04:15:56.417

Modified: 2025-11-29T04:15:56.417

Link: CVE-2025-65540

cve-icon Redhat

No data.