Impact
A cross‑site scripting vulnerability is present in itsourcecode Fees Management System versions 1.0 and earlier, located in the /navbar.php file. By manipulating the page argument in a request, an attacker can inject arbitrary JavaScript that is reflected back to the victim, potentially allowing session hijacking, defacement, or other client‑side attacks. The issue is associated with CWE‑79 and CWE‑94, indicating weaknesses in input handling and unsafe code execution respectively.
Affected Systems
The affected product is itsourcecode Fees Management System, with all releases up to version 1.0 vulnerable. The flaw resides in the function within /navbar.php that processes the page parameter. Users who have not applied a corrective patch remain exposed.
Risk and Exploitability
The CVSS score of 5.3 classifies the issue as medium severity. The vulnerability can be triggered remotely by sending a crafted request that manipulates the page argument, and exploit code has been released publicly. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the combination of remote triggerability and publicly available exploit code makes it a realistic threat to affected installations.
OpenCVE Enrichment