Impact
A reflected cross‑site scripting flaw exists in the CommentSave.php file of the code‑projects Task Management System 1.0. By modifying the comment, task_id, mineId, recId, myName, or myImage arguments, an attacker can inject arbitrary JavaScript. When the affected page is rendered, the injected script runs in the victim’s browser, potentially allowing session hijacking, credential theft, defacement, or other secondary attacks. The flaw is classified as CWE‑79 for cross‑site scripting and CWE‑94 for potential code injection techniques.
Affected Systems
Only the 1.0 release of the code‑projects Task Management System is known to be vulnerable. No other versions or products have been reported as affected, and the vendor’s repository does not yet list a fixed release.
Risk and Exploitability
The CVSS score of 5.3 signals a moderate risk level. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely by crafting a URL or form submission that supplies malicious values for the exposed parameters. It can be inferred from the description that the victim must visit the vulnerable web page for the payload to execute, as no other side‑channel or network‑level exploitation is described. The exposure requires only standard web traffic and does not demand elevated privileges or privileged network access.
OpenCVE Enrichment