{"id":72389,"date":"2025-10-27T09:45:38","date_gmt":"2025-10-27T06:15:38","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/cve-2025-12229-projectworlds-expense-management-system-roles-page-create-cross-site-scripting\/"},"modified":"2025-10-27T09:45:38","modified_gmt":"2025-10-27T06:15:38","slug":"cve-2025-12229-projectworlds-expense-management-system-roles-page-create-cross-site-scripting","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cve-2025-12229-projectworlds-expense-management-system-roles-page-create-cross-site-scripting\/","title":{"rendered":"CVE-2025-12229 &#8211; projectworlds Expense Management System Roles Page create cross site scripting"},"content":{"rendered":"<p>CVE ID : CVE-2025-12229<\/p>\n<p>Published :  Oct. 27, 2025, 6:15 a.m. | 29\u00a0minutes ago<\/p>\n<p>Description : A security flaw has been discovered in projectworlds Expense Management System 1.0. This affects an unknown function of the file \/public\/admin\/roles\/create of the component Roles Page. The manipulation results in cross site scripting. The attack may be performed from remote. The exploit has been released to the public and may be exploited.<\/p>\n<p>Severity: 4.8 | MEDIUM<\/p>\n<p>Visit the link for more details, such as CVSS details, affected products, timeline, and more&#8230;\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE ID : CVE-2025-12229 Published : Oct. 27, 2025, 6:15 a.m. | 29\u00a0minutes ago Description : A security flaw has been discovered in projectworlds Expense Management System 1.0. This affects an unknown function of the file \/public\/admin\/roles\/create of the component Roles Page. The manipulation results in cross site scripting. The attack may be performed from &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-72389","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/72389","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=72389"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/72389\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=72389"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=72389"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=72389"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}