{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2025-1155","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2025-02-10T07:40:07.691Z","datePublished":"2025-02-10T20:00:13.333Z","dateUpdated":"2025-02-10T20:51:58.656Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2025-02-10T20:00:13.333Z"},"title":"Webkul QloApps Your Location Search stores cross site scripting","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-79","lang":"en","description":"Cross Site Scripting"}]},{"descriptions":[{"type":"CWE","cweId":"CWE-94","lang":"en","description":"Code Injection"}]}],"affected":[{"vendor":"Webkul","product":"QloApps","versions":[{"version":"1.6.1","status":"affected"}],"modules":["Your Location Search"]}],"descriptions":[{"lang":"en","value":"A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. This affects an unknown part of the file /stores of the component Your Location Search. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. It is planned to remove this page in the long term."},{"lang":"de","value":"Es wurde eine problematische Schwachstelle in Webkul QloApps 1.6.1 gefunden. Betroffen hiervon ist ein unbekannter Ablauf der Datei /stores der Komponente Your Location Search. Mittels Manipulieren mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":5.3,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":4.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":4.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":5,"vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N"}}],"timeline":[{"time":"2025-02-10T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2025-02-10T01:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2025-02-10T08:45:13.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"Mahendravarman (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/?id.295059","name":"VDB-295059 | Webkul QloApps Your Location Search stores cross site scripting","tags":["vdb-entry"]},{"url":"https://vuldb.com/?ctiid.295059","name":"VDB-295059 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.492777","name":"Submit #492777 | Webkul QloApps v1.6.1 Cross Site Scripting","tags":["third-party-advisory"]},{"url":"https://github.com/mano257200/Qloapp-XSS-Vulnerability/tree/main","tags":["related"]}]},"adp":[{"references":[{"url":"https://github.com/mano257200/Qloapp-XSS-Vulnerability/tree/main","tags":["exploit"]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-02-10T20:51:54.304091Z","id":"CVE-2025-1155","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-02-10T20:51:58.656Z"}}]}}