A flaw has been found in Bdtask/CodeCanyon SalesERP up to 20250728. This vulnerability affects unknown code of the file /edit_profile of the component User Profile Handler. This manipulation of the argument first_name/last_name causes basic cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
History

Sat, 15 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Bdtask
Bdtask saleserp
Codecanyon
Codecanyon saleserp
Vendors & Products Bdtask
Bdtask saleserp
Codecanyon
Codecanyon saleserp

Fri, 14 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 14 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Bdtask/CodeCanyon SalesERP up to 20250728. This vulnerability affects unknown code of the file /edit_profile of the component User Profile Handler. This manipulation of the argument first_name/last_name causes basic cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Bdtask/CodeCanyon SalesERP User Profile edit_profile cross site scripting
Weaknesses CWE-74
CWE-80
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-11-14T19:02:10.138Z

Updated: 2025-11-14T21:40:01.378Z

Reserved: 2025-11-14T11:01:40.704Z

Link: CVE-2025-13178

cve-icon Vulnrichment

Updated: 2025-11-14T21:39:47.055Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-14T19:15:58.210

Modified: 2025-11-18T14:06:55.963

Link: CVE-2025-13178

cve-icon Redhat

No data.