Threats Tagged 'cve-2025-12289'
View all threats tagged with 'cve-2025-12289'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-12289'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2025-12289 is a medium-severity cross-site scripting (XSS) vulnerability found in version 1.0 of the Suishang Enterprise-Level B2B2C Multi-User Mall System by Sui Shang Information Technology. The vulnerability exists in the handling of the category_id parameter within the /Point/index/activity_state/1/category_id/1001 endpoint, allowing remote attackers to inject malicious scripts without authentication. Exploitation requires user interaction but no privileges, potentially leading to limited integrity and confidentiality impacts such as session hijacking or phishing. The vendor has not responded to disclosure requests, and no patches are currently available. European organizations using this e-commerce platform could face targeted attacks, especially in countries with higher adoption of this software or significant B2B2C marketplaces. Mitigation involves input validation, web application firewalls, and user awareness. Given the CVSS 5.3 score and attack vector, the threat is moderate but should be addressed promptly to prevent exploitation. Join the discussion | CVE Database V5 | 10/27/2025, 15:02:05 UTC Added: 10/27/2025, 15:07:48 UTC |
Showing 1 to 1 of 1 result