CVE-2025-9237 – CodeAstro Ecommerce Website Cross Site Scripting

The following table lists the changes that have been made to the
CVE-2025-9237 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Aug. 20, 2025

    Action Type Old Value New Value
    Added Description A vulnerability was found in CodeAstro Ecommerce Website 1.0. This impacts an unknown function of the file /customer/my_account.php?edit_account of the component Edit Your Account Page. Performing manipulation of the argument Username results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
    Added CVSS V4.0 AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CVSS V3.1 AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
    Added CVSS V2 (AV:N/AC:L/Au:S/C:N/I:P/A:N)
    Added CWE CWE-79
    Added CWE CWE-94
    Added Reference https://codeastro.com/
    Added Reference https://gist.github.com/0xSebin/bb6781e5977bda36610fda20861a5bbe
    Added Reference https://gist.github.com/0xSebin/bb6781e5977bda36610fda20861a5bbe#steps-to-reproduce
    Added Reference https://vuldb.com/?ctiid.320770
    Added Reference https://vuldb.com/?id.320770
    Added Reference https://vuldb.com/?submit.631136
Share the Post:

Related Posts