CVE-2025-65233
EUVD-2025-20391617.12.2025, 20:15
Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF' ] in index.php/sysconfig.inc.php, which allows remote attackers to execute arbitrary JavaScript in a victim's browser by supplying a crafted URL path.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| slims_project | slims | 𝑥 < 9.6.0 |
𝑥
= Vulnerable software versions