Skip to main content

Threats Tagged 'cve-2025-12289'

View all threats tagged with 'cve-2025-12289'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2025-12289

Threats Tagged 'cve-2025-12289'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2025-12289 is a medium-severity cross-site scripting (XSS) vulnerability found in version 1.0 of the Suishang Enterprise-Level B2B2C Multi-User Mall System by Sui Shang Information Technology. The vulnerability exists in the handling of the category_id parameter within the /Point/index/activity_state/1/category_id/1001 endpoint, allowing remote attackers to inject malicious scripts without authentication. Exploitation requires user interaction but no privileges, potentially leading to limited integrity and confidentiality impacts such as session hijacking or phishing. The vendor has not responded to disclosure requests, and no patches are currently available. European organizations using this e-commerce platform could face targeted attacks, especially in countries with higher adoption of this software or significant B2B2C marketplaces. Mitigation involves input validation, web application firewalls, and user awareness. Given the CVSS 5.3 score and attack vector, the threat is moderate but should be addressed promptly to prevent exploitation.

Join the discussion

Showing 1 to 1 of 1 result

Filters:Tag: cve-2025-12289
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses