Impact
A stored cross site scripting vulnerability exists in the admin index page of the system settings module in SourceCodester Online Book Store System 1.0. The flaw allows an attacker to inject arbitrary scripts that are executed in the context of a victim’s browser when the affected page is viewed. This can lead to data theft, session hijacking, or defacement of the site. The weakness is classified as a CWE‑79 type input validation problem.
Affected Systems
The vulnerable component is part of SourceCodester’s Online Book Store System 1.0. The attack vector is a remote request to the /admin/index.php page with a malicious page parameter set to site_settings. No earlier versions are mentioned as affected; the single known affected product is the 1.0 release of the online book store system.
Risk and Exploitability
The CVSS base score of 4.8 indicates a moderate impact, but the fact that the exploit code is publicly available and can be executed remotely increases the threat. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack does not mention a need for privileged access, suggesting that any authenticated administrator or possibly even unauthenticated users with the ability to view the admin page could be harmed. Given the lack of a public patch, the risk remains high until mitigation measures are applied.
OpenCVE Enrichment