Impact
A vulnerability exists in the offersmail.php component of code‑projects Online Shopping System version 1.0 where manipulation of the email argument can lead to cross‑site scripting (CWE‑79). The flaw enables an attacker to inject arbitrary client‑side scripts through the email parameter, which can then execute in the browser of any user that views the affected page. This weakness is an instance of improper input validation that can also facilitate code injection (CWE‑94) under certain circumstances. The impact is a breach of confidentiality and integrity of the client environment, potentially allowing an attacker to steal session cookies, deface the site, or perform phishing attacks.
Affected Systems
The affected system is code‑projects Online Shopping System version 1.0, with no other versions explicitly mentioned in the CVE data. All installations of this product that utilize the offersmail.php file without proper input validation are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely, and exploit code has been made publicly available, increasing the likelihood of real‑world attacks.
OpenCVE Enrichment