Junglewise Threat Intelligence

CVE-2025-8411: Dokuzsoft Technology E-Commerce XSS via HTTP headers

CVE-2025-8411 · Severity: high · CVSS 7.1 · Published 2025-09-17

Executive brief

Dokuzsoft Technology's e-commerce platform contains a security flaw that could allow attackers to execute malicious scripts in a user's browser. This occurs when the system fails to properly clean data sent through web request headers before displaying it on a page. If exploited, an attacker could potentially steal customer session information, redirect users to fraudulent websites, or perform unauthorized actions on behalf of a logged-in user.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Dokuzsoft Technology E-Commerce Web Design Product due to improper neutralization of input during web page generation. Specifically, the application fails to sanitize data received through HTTP headers before reflecting it in the response body. An unauthenticated remote attacker can exploit this by tricking a user into visiting a specially crafted link or by manipulating headers in a way that executes arbitrary JavaScript in the context of the victim's browser session. This can lead to the theft of sensitive information such as session cookies or the performance of unauthorized actions. The issue is addressed in versions released on or after August 11, 2025.

Affected products

  • Dokuzsoft Technology E-Commerce Web Design Product before 11.08.2025

Timeline

  • 2025-08-11: patched: Fix released for E-Commerce Web Design Product
  • 2025-09-17: disclosed: Initial advisory publication

References