{"id":"CVE-2025-57768","summary":"Stored XSS in “hours” fields when creating or editing an issue, using SQLite database","details":"Phproject is a high performance full-featured project management system. From 1.8.0 to before 1.8.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Planned Hours field when creating a new project. When sending a POST request to /issues/new/, the value provided in the Planned Hours field is included in the server response without any HTML encoding or sanitization. Because of this, an attacker can craft a malicious payload such as \u003cscript\u003ealert(1)\u003c/script\u003e and include it in the planned_hours parameter. The server reflects the input directly in the HTML of the project creation page, causing the browser to interpret and execute it. This vulnerability is fixed in 1.8.3.","aliases":["GHSA-mhhg-qx37-g369"],"modified":"2026-07-15T01:49:14.363515883Z","published":"2025-08-21T17:20:35.531Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/57xxx/CVE-2025-57768.json"},"references":[{"type":"ADVISORY","url":"https://github.com/Alanaktion/phproject/security/advisories/GHSA-mhhg-qx37-g369"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/57xxx/CVE-2025-57768.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-57768"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/alanaktion/phproject","events":[{"introduced":"a77e05228a18875ed2ee5868aea9c9456b4f7455"},{"fixed":"5970d68d480a1db87f87ed377aa77194db192d28"}],"database_specific":{"extracted_events":[{"introduced":"1.8.0"},{"fixed":"1.8.3"},{"introduced":"0"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["v1.8.2","v1.8.1","v1.8.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-57768.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}]}