Impact
A vulnerability in the index.php file of itsourcecode Courier Management System allows manipulation of the page query parameter by a remote user, enabling injection of arbitrary client‑side scripts. This cross‑site scripting flaw permits execution of malicious code in the victim’s browser context. The description does not specify the precise impact beyond script execution, so consequential effects such as session hijacking or defacement are inferred but not confirmed.
Affected Systems
The flaw affects all installations of itsourcecode Courier Management System version 1.0 and earlier. The issue originates in the /index.php entry point and is triggered by the page parameter supplied by a user.
Risk and Exploitability
The CVSS score is 5.3, indicating a moderate severity. The EPSS score is less than 1 %, implying a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers can remotely exploit the flaw by delivering a crafted request that sets the page parameter to contain malicious JavaScript, which then executes in the victim’s browser.
OpenCVE Enrichment