CVE-2025-13178 is a medium-severity cross-site scripting (XSS) vulnerability affecting Bdtask/CodeCanyon SalesERP up to version 20250728. Specifically, it allows for basic XSS through manipulation of the first_name/last_name arguments in the /edit_profile component. The vulnerability has a CVSS score of 5.4, indicating a remote attack with low privileges required, but user interaction is necessary for exploitation, leading to low impact on confidentiality and integrity. While an exploit has been published, there is no evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2025-10-24CPE matchmatch criteria | cpe:2.3:a:bdtask:saleserp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.