A weakness has been identified in projectworlds Expense Management System 1.0. This impacts an unknown function of the file /public/admin/currencies/create of the component Currency Page. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.
History

Tue, 28 Oct 2025 02:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:projectworlds:expense_management_system:1.0:*:*:*:*:*:*:*

Mon, 27 Oct 2025 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Projectworlds
Projectworlds expense Management System
Vendors & Products Projectworlds
Projectworlds expense Management System

Mon, 27 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Oct 2025 06:15:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in projectworlds Expense Management System 1.0. This impacts an unknown function of the file /public/admin/currencies/create of the component Currency Page. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.
Title projectworlds Expense Management System Currency create cross site scripting
Weaknesses CWE-79
CWE-94
References
Metrics cvssV2_0

{'score': 3.3, 'vector': 'AV:N/AC:L/Au:M/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 2.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 2.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-10-27T06:02:06.014Z

Updated: 2025-10-27T15:15:26.294Z

Reserved: 2025-10-25T17:00:35.913Z

Link: CVE-2025-12230

cve-icon Vulnrichment

Updated: 2025-10-27T15:15:03.961Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-27T06:15:38.790

Modified: 2025-10-28T02:17:40.037

Link: CVE-2025-12230

cve-icon Redhat

No data.