CVE-2025-3975 Details
Description
A vulnerability was found in ScriptAndTools eCommerce-website-in-PHP 3.0 and classified as problematic. This issue affects some unknown processing of the file /admin/subscriber-csv.php. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
An information disclosure vulnerability has been identified in ScriptAndTools eCommerce-website-in-PHP version 3.0. The issue arises from improper access controls in the file subscriber-csv.php, located in the admin directory. This vulnerability allows unauthorized access to subscriber data, which can be exploited remotely, leading to potential privacy violations and reputational damage.
Implement proper access controls to ensure that sensitive data can only be accessed by authorized users. Regularly audit and monitor access logs to detect and respond to unauthorized access attempts.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.websecurityinsights.my.id/2025/04/script-and-tools-ecommerce-30_53.html | CISA-ADP | ExploitThird Party Advisory |
| https://vuldb.com/?ctiid.306311 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.306311 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.557414 | [email protected] | Third Party AdvisoryVDB Entry |
| https://www.websecurityinsights.my.id/2025/04/script-and-tools-ecommerce-30_53.html | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| scriptandtools ecommerce-website-in-php | 3.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 12, 2025 | Initial Analysis | [email protected] |
| Apr 28, 2025 | CVE Modified | CISA-ADP |
| Apr 27, 2025 | New CVE Received | [email protected] |