A vulnerability categorized as problematic has been discovered in xmall 1.1. This impacts an unknown function. Such manipulation leads to cross site scripting.

This vulnerability is uniquely identified as CVE-2025-65540. The attack can be launched remotely. No exploit exists.