
Proof of Concept for CVE-2025-56762
The application leverages “error.php” to serve the respective error code as per the use case back to the web application upon encountering an error. Upon inspecting the source code, it was found that the application does not sanitize the parameter “code” when crafting a malicious Javascript code resulting in execution.
Successful exploitation of this allows execution of malicious scripts in a user's browser, leading to data theft, account hijacking, and web page manipulation
/error.php?code=">