Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-14221 — Proof-of-concept for CVE-2025-14221: Stored XSS in SourceCodester Online Banking System 1.0 via unsanitized First Name field, enabling session hijacking and account takeover. | Kitploit
Tools/GitHubGitHub/fatmatrabelsi17/cve-2025-14221
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubfatmatrabelsi17/cve-2025-14221

CVE-2025-14221

Proof-of-concept for CVE-2025-14221: Stored XSS in SourceCodester Online Banking System 1.0 via unsanitized First Name field, enabling session hijacking and account takeover.

View Repository
19 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Description

  1. CVE-2025-14221
  2. Discoverer: Fatma Trabelsi
  3. Vendor of Product: SourceCodester
  4. Affected Product: Online Banking System 1.0

POC

A Stored Cross-Site Scripting (XSS) vulnerability exists in the User Profile Update functionality of the application. The application fails to properly sanitize user‑supplied input in the First Name field before storing it in the database and rendering it across multiple pages.

An attacker can inject arbitrary JavaScript code into the First Name field, which will be executed every time any user (including administrators) views a page where that profile information is displayed. This allows attackers to perform actions such as session hijacking, credential theft, DOM manipulation, and full takeover of any account that loads the malicious profile data.

References

https://nvd.nist.gov/vuln/detail/CVE-2025-14221

https://www.cve.org/CVERecord?id=CVE-2025-14221

https://github.com/advisories/GHSA-mr7v-3qmp-fjc4

https://mega.nz/file/T4hjCagS#87U1JgRHZWzXW2HTpBIG-H9dJ_w9kUERmaaQqJyB5_Q

https://vuldb.com/?id.334663

Download Tool