Home
Description
Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF' ] in index.php/sysconfig.inc.php, which allows remote attackers to execute arbitrary JavaScript in a victim's browser by supplying a crafted URL path.
References
github.com/slims/slims9_bulian/issues/185
github.com/...ulnerability-research/tree/main/CVE-2025-65233
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.