Severity
5.3MEDIUM
EPSS
0.0%
top 89.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 27

Description

A weakness has been identified in code-projects Simple Food Ordering System 1.0. This issue affects some unknown processing of the file /addcategory.php. This manipulation of the argument cname causes cross site scripting. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-rwf6-2p77-cj6v: A weakness has been identified in code-projects Simple Food Ordering System 12025-10-27
CVEList
code-projects Simple Food Ordering System addcategory.php cross site scripting2025-10-27
CVE-2025-12300 (MEDIUM CVSS 5.3) | A weakness has been identified in c | cvebase.io