Impact
The vulnerability permits the injection of arbitrary JavaScript through manipulation of the Username argument supplied to login_register.php. This flaw leads to an XSS vulnerability that can execute scripts within the victim’s browser, potentially allowing defacement, information theft, or other malicious actions that affect the confidentiality or integrity of user data.
Affected Systems
The flaw exists in the yashpokharna2555 restaurent‑management‑system web application. Because the project follows a rolling release model, no specific versions are listed for affected or fixed releases, meaning all current and future releases may contain the vulnerability until a patched commit is released.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. EPSS data is not available and the vulnerability is not in CISA’s KEV catalog. A public exploit has been released, and an attacker can initiate the attack remotely by sending a crafted request to the registration endpoint. While the exact impact depends on the context in which the script runs, XSS can compromise user sessions, steal credentials, or deface content, posing a moderate risk to authenticated and unauthenticated users alike.
OpenCVE Enrichment