Impact
The vulnerability lies in the checkout.php file of Online Shopping System 1.0. By manipulating the amount_1 parameter, an attacker can inject malicious scripts that are executed in the victim’s browser. This leads to the ability to run arbitrary client‑side code, potentially hijacking user sessions, defacing pages, or phishing for credentials. The flaw is a classic reflected XSS flaw classified as CWE‑79, and it also involves an unsupported code execution path signified by CWE‑94.
Affected Systems
The affected vendor is code‑projects with the product Online Shopping System, version 1.0. No other versions or products are currently listed as affected.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity. The EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited proof‑of‑concepts in production. The attack can be initiated remotely via HTTP requests supplied by an attacker, and the exploit code has already been publicly released.
OpenCVE Enrichment