---
id: CVE-2025-12230
title: A weakness has been identified in projectworlds Expense Management System 1.0
summary: >-
  A weakness has been identified in projectworlds Expense Management System 1.0.
  This impacts an unknown function of the file /public/admin/currencies/create
  of the component Currency Page. This manipulation causes cross site scripting.
  It…
severity: low
cvss: 2.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
vendor: projectworlds
product: expense_management_system
affected:
  - expense_management_system = 1.0
published: '2025-10-27'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-12230'
references:
  - url: 'https://github.com/QIU-DIE/CVE/issues/11'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.329900'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.329900'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.673707'
    label: cna@vuldb.com
  - url: 'https://github.com/QIU-DIE/CVE/issues/11'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00259
epssPercentile: 0.16131
ingestedAt: '2026-10-08T11:31:27.619Z'
---

## Overview

A weakness has been identified in projectworlds Expense Management System 1.0. This impacts an unknown function of the file /public/admin/currencies/create of the component Currency Page. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.

## Affected

- `expense_management_system = 1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
