can lead to","datePublished":"2025-09-09T01:02:10.703000+00:00","dateModified":"2025-09-09T19:23:08.178000+00:00","inLanguage":"pt","author":{"@type":"Organization","name":"Vexday"},"publisher":{"@type":"Organization","name":"Vexday","url":"https://vexday.io"},"mainEntityOfPage":"https://vexday.io/pt/cve/CVE-2025-10117","keywords":"CVE-2025-10117, CWE-79, CWE-94","breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Início","item":"https://vexday.io/pt"},{"@type":"ListItem","position":2,"name":"CVE-2025-10117"}]}}← voltar
CVE-2025-10117

SourceCodester Simple To-Do List System Add New Task fetch_tasks.php cross site scripting

CVSS 5.1 MEDIUMEPSS 0.3%CWE-79CWE-94
A weakness has been identified in SourceCodester Simple To-Do List System 1.0. Impacted is an unknown function of the file /fetch_tasks.php of the component Add New Task. Executing manipulation with the input <script>alert('XSS')</script> can lead to cross site scripting. The attack can be executed remotely. The exploit has been made available to the public and could be exploited.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →