CVE-2025-14201 is a Cross-Site Scripting (XSS) vulnerability affecting alokjaiswal Hotel-Management-services-using-MYSQL-and-php up to commit 5f8b60a7aa6c06a5632de569d4e3f6a8cd82f76f, specifically within the /dishsub.php file when manipulating the 'item.name' argument. This vulnerability has a CVSS score of 4.8 (Medium), indicating it can be exploited remotely with low attack complexity, requiring high privileges and user interaction, potentially leading to limited impact on confidentiality and integrity. While the exploit has been made public, there is no evidence of active exploitation, and it lacks exploit intelligence in Metasploit, Nuclei, or ExploitDB, with minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2018-11-08CPE matchmatch criteria | cpe:2.3:a:alokjaiswal:hotel-management-services-using-mysql-and-php:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.