Impact
A flaw in SourceCodester Simple Responsive Tourism Website 1.0 exists in the registration handling script Master.php. Manipulating the firstname, lastname or username input fields injects arbitrary client‑side script into the page rendered after registration. The vulnerability enables remote execution of that script when a user visits the resulting page, and published exploit code confirms the flaw can be used from outside the system.
Affected Systems
The affected vendor is SourceCodester and the product is Simple Responsive Tourism Website version 1.0. No other versions or sub‑products are listed as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity while the EPSS score of less than 1% shows a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation is possible remotely via HTTP requests that supply malicious values to the registration endpoint, and the existence of publicly available exploit code demonstrates feasibility.
OpenCVE Enrichment