CVE-2025-66845
Unknown
Unknown - Not Provided
Reflected XSS in TechStore 1.0 user_name Endpoint Enables Code Execution
Publication date: 2025-12-23
Last updated on: 2025-12-23
Assigner: MITRE
Description
Description
A reflected Cross-Site Scripting (XSS) vulnerability has been identified in TechStore version 1.0. The user_name endpoint reflects the id query parameter directly into the HTML response without output encoding or sanitization, allowing execution of arbitrary JavaScript code in a victimβs browser.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| techstore | techstore | 1.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |