Impact
The vulnerability resides in the photo‑sharing website’s home page, where an attacker can manipulate the Comment input to inject malicious scripts. This flaw is a classic reflected XSS, described as CWE‑79, and can also trigger code injection (CWE‑94). Once executed, the injected script runs with the victim’s browser context, potentially allowing cookie theft, session hijacking, defacement, or phishing attempts. The impact is limited to the compromised user’s browser but can be leveraged for credential theft or create a foothold for further social engineering.
Affected Systems
SourceCodester Photo Share Website 1.0 is the only affected product. No other versions or downstream components are listed in the cpe data, and the vendor’s advisory indicates the flaw exists in the single 1.0 release.
Risk and Exploitability
The CVSS score of 5.1 places this vulnerability in the medium severity range. EPSS is not available, but the public exploit exists and can be triggered remotely by supplying a crafted Comment parameter. The flaw is not catalogued in CISA KEV, but the presence of a published exploit means the likelihood of use is non‑trivial. Administrators should treat this as a moderate‑to‑high risk for users who can add content via the home page and should remediate promptly.
OpenCVE Enrichment