A security flaw has been discovered in projectworlds Expense Management System 1.0. This affects an unknown function of the file /public/admin/roles/create of the component Roles Page. The manipulation results in cross site scripting. The attack may be performed from remote. The exploit has been released to the public and may be exploited.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/QIU-DIE/CVE/issues/10 | Exploit Issue Tracking | 
| https://vuldb.com/?ctiid.329899 | Permissions Required VDB Entry | 
| https://vuldb.com/?id.329899 | Third Party Advisory VDB Entry | 
| https://vuldb.com/?submit.673706 | Third Party Advisory VDB Entry | 
Configurations
                    History
                    28 Oct 2025, 02:17
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:projectworlds:expense_management_system:1.0:*:*:*:*:*:*:* | |
| References | () https://github.com/QIU-DIE/CVE/issues/10 - Exploit, Issue Tracking | |
| References | () https://vuldb.com/?ctiid.329899 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.329899 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.673706 - Third Party Advisory, VDB Entry | |
| First Time | Projectworlds expense Management System Projectworlds | 
27 Oct 2025, 06:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-10-27 06:15
Updated : 2025-10-28 02:17
NVD link : CVE-2025-12229
Mitre link : CVE-2025-12229
CVE.ORG link : CVE-2025-12229
JSON object : View
Products Affected
                projectworlds
- expense_management_system
