Skip to main content

CVE-2025-6345: Rems My Food Recipe XSS Vulnerability

CVE-2025-6345 is a cross site scripting flaw in Rems My Food Recipe 1.0 affecting the Add Recipe page. Attackers can exploit this remotely through the Name parameter. This post explains technical details, affected versions, impact, and mitigation steps.

Published:

CVE-2025-6345 Overview

CVE-2025-6345 is a cross-site scripting (XSS) vulnerability in SourceCodester My Food Recipe 1.0. The flaw resides in the addRecipeModal function within /endpoint/add-recipe.php, part of the Add Recipe Page component. Attackers can manipulate the Name parameter to inject arbitrary JavaScript into the application. The attack is remotely exploitable and requires low privileges plus user interaction. Public disclosure of the exploit has occurred through VulDB and a GitHub proof-of-concept repository. The issue is tracked under CWE-79 (Improper Neutralization of Input During Web Page Generation).

Critical Impact

Successful exploitation allows attackers to execute arbitrary JavaScript in the browsers of users who view attacker-controlled recipe entries, enabling session theft, credential harvesting, or unauthorized actions performed on behalf of the victim.

Affected Products

  • SourceCodester My Food Recipe 1.0
  • Component: Add Recipe Page (/endpoint/add-recipe.php)
  • Function: addRecipeModal

Discovery Timeline

  • 2025-06-20 - CVE-2025-6345 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-6345

Vulnerability Analysis

The vulnerability is a stored or reflected cross-site scripting flaw introduced by unsanitized handling of the Name argument passed to addRecipeModal in /endpoint/add-recipe.php. When an authenticated user submits a new recipe, the Name field is written back to the page without proper HTML encoding or input filtering. Any HTML or JavaScript payload supplied in that field is rendered by the browser as executable content. Because the exploit is publicly documented, opportunistic attackers can weaponize it against exposed instances with minimal effort.

Root Cause

The underlying defect is improper neutralization of user-supplied input during page generation, classified as CWE-79. The add-recipe.php endpoint fails to apply output encoding on the Name parameter before embedding it in the HTML response. There is no allowlist validation on the field and no context-aware escaping applied at the template layer.

Attack Vector

An attacker with a low-privilege authenticated account submits a recipe whose Name field contains a JavaScript payload such as an <script> tag or an HTML attribute with a on* event handler. When another user, including an administrator, browses the page rendering that recipe, the injected code executes in the victim's browser under the origin of the vulnerable application. Consult the GitHub proof-of-concept repository for payload details.

// No verified exploit code is reproduced here.
// Refer to the linked PoC repository for the documented payload.

Detection Methods for CVE-2025-6345

Indicators of Compromise

  • Recipe entries containing HTML tags such as <script>, <img onerror=, or <svg onload= in the Name field.
  • Outbound HTTP requests from user browsers to unfamiliar domains shortly after loading pages that render recipe content.
  • Web server access logs showing POST requests to /endpoint/add-recipe.php with encoded angle brackets or JavaScript keywords in the Name parameter.

Detection Strategies

  • Inspect the recipes database table for entries whose Name column contains HTML control characters or JavaScript keywords such as alert(, document.cookie, or fetch(.
  • Deploy a web application firewall (WAF) rule that flags XSS payload patterns targeting the Name field of the Add Recipe endpoint.
  • Correlate authentication logs with recipe submissions to identify low-privileged accounts producing suspicious content.

Monitoring Recommendations

  • Enable verbose logging on /endpoint/add-recipe.php and forward events to a centralized log platform.
  • Alert on any Content Security Policy (CSP) violation reports generated by pages that display recipe data.
  • Track admin session activity for anomalous requests performed immediately after viewing user-submitted recipes.

How to Mitigate CVE-2025-6345

Immediate Actions Required

  • Restrict access to the Add Recipe Page to trusted users until a code-level fix is applied.
  • Purge or sanitize existing recipe entries containing HTML or script content in the Name field.
  • Enforce a strict Content Security Policy that disallows inline scripts to reduce exploitation impact.

Patch Information

No official vendor patch has been published for SourceCodester My Food Recipe 1.0 at the time of the NVD entry. Administrators should implement server-side input validation on the Name parameter and apply context-appropriate HTML entity encoding before rendering user-supplied data. Refer to the VulDB advisory for tracking updates.

Workarounds

  • Apply server-side output encoding using PHP functions such as htmlspecialchars($name, ENT_QUOTES, 'UTF-8') before rendering the Name value.
  • Deploy a WAF ruleset that blocks common XSS payloads submitted to /endpoint/add-recipe.php.
  • Configure a restrictive CSP header, for example Content-Security-Policy: default-src 'self'; script-src 'self'.
bash
# Example nginx configuration to add a restrictive CSP header
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'" always;
add_header X-Content-Type-Options "nosniff" always;
add_header X-Frame-Options "DENY" always;

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.