CVE-2025-60280

Cross-Site Scripting (XSS) vulnerability in Bang Resto v1.0 could allow an attacker to inject malicious JavaScript code into the application's web pages. This vulnerability exists due to insufficient input sanitization or output encoding, allowing attacker-controlled input to be rendered directly in the browser. When exploited, an attacker can steal session cookies, redirect users to malicious sites, perform actions on behalf of the user, or deface the website. This can lead to user data compromise, loss of user trust, and a broader attack surface for more advanced exploitation techniques.
Configurations

No configuration.

History

21 Oct 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-21 16:15

Updated : 2025-10-21 19:31


NVD link : CVE-2025-60280

Mitre link : CVE-2025-60280

CVE.ORG link : CVE-2025-60280


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')