CVE-2025-57204
Last modified
CVE-2025-57204 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Stocky POS with Inventory Management & HRM (ui-lib) version 5.0 is affected by a Stored Cross-Site Scripting (XSS) vulnerability within the Products module available to authenticated users. The vulnerability resides in the product name parameter submitted to the product-creation endpoint via a standard POST form. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
Stocky POS with Inventory Management & HRM (ui-lib) version 5.0 is affected by a Stored Cross-Site Scripting (XSS) vulnerability within the Products module available to authenticated users. The vulnerability resides in the product name parameter submitted to the product-creation endpoint via a standard POST form. Due to insufficient input sanitization and output encoding, attackers can inject HTML/JS payloads. The payload is stored and subsequently rendered unsanitized in downstream views, leading to JavaScript execution in other users' browsers when they access the affected product pages. This issue allows an authenticated attacker to execute arbitrary JavaScript in the context of another user, potentially enabling session hijacking, privilege escalation within the application, data exfiltration, or administrative account takeover. The application also lacks a restrictive Content Security Policy (CSP), increasing exploitability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ui-Lib | Stocky | 5.0 |
References
- https://grumpz.net/cve-2025-57204-stored-xss-in-stocky-pos-with-inventory-management-and-hrm-ui-lib-50Exploit, Third Party Advisory
- https://grumpz.net/cve-2025-57204-stored-xss-in-stocky-pos-with-inventory-management-and-hrm-ui-lib-50Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-57204?
How severe is CVE-2025-57204?
How do I fix CVE-2025-57204?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-57199AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1…8.8
- CVE-2025-5720The Customer Reviews for WooCommerce plugin for WordPress is…6.4
- CVE-2025-57200AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1…6.5
- CVE-2025-57201AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1…8.8
- CVE-2025-57202A stored cross-site scripting (XSS) vulnerability in the Pwd…6.1
- CVE-2025-57203MagicProject AI version 9.1 is affected by a Cross-Site Scri…4.8
- CVE-2025-57205iNiLabs School Express (SMS Express) 6.2 is affected by a St…5.4
- CVE-2025-5721A vulnerability, which was classified as problematic, was fo…5.4
- CVE-2025-57210Incorrect access control in the component ApiPayController.j…7.5
- CVE-2025-57212Incorrect access control in the component ApiOrderService.ja…7.5
- CVE-2025-57213Incorrect access control in the component orderService.query…7.5
- CVE-2025-57215Tenda AC10 v4.0 firmware v16.03.10.20 was discovered to cont…7.5
Are you affected by CVE-2025-57204?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
