CVE-2025-60302

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
09/10/2025
Last modified:
29/10/2025

Description

code-projects Client Details System 1.0 is vulnerable to Cross Site Scripting (XSS). When adding customer information, the client details system fills in malicious JavaScript code in the username field.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fabian:client_details_system:1.0:*:*:*:*:*:*:*