CVE-2025-56289

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
16/09/2025
Last modified:
18/09/2025

Description

code-projects Document Management System 1.0 has a Cross Site Scripting (XSS) vulnerability, where attackers can leak admin's cookie information by entering malicious XSS code in the Company field when adding files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fabian:document_management_system:1.0:*:*:*:*:*:*:*