Description

Sourcecodester AI-Powered To-Do List App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Task Title" and "Description (Optional)" fields when creating a Task, allowing an attacker to inject arbitrary potentially malicious HTML/JavaScript code that executes in the victim's browser upon clicking the "Add Task" button.

INFO

Published Date :

2025-11-07T00:00:00.000Z

Last Modified :

2025-11-12T19:53:48.931Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-63638 vulnerability.

Vendors Products
Remyandrade
  • Ai-powered To-do List App
Sourcecodester
  • Ai Powered To Do List App

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact