Security Advisory

CVE-2025-57425

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-08-26 00:00:00
Last updated 2025-08-27 16:01:58
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

A Stored Cross-Site Scripting (XSS) vulnerability in SourceCodester FAQ Management System 1.0 allows an authenticated attacker to inject malicious JavaScript into the 'question' and 'answer' fields via the update-faq.php endpoint.