Impact
Affected is a part of the btn_functions.php file in the Online Reviewer System. The firstname parameter, when manipulated, results in cross‑site scripting, allowing an attacker to execute arbitrary script in a browser context. The vulnerability is classified as CWE‑79 and may also involve CWE‑94.
Affected Systems
The vulnerability impacts the code‑projects Online Reviewer System version 1.0. The problematic code resides in the manage/users/btn_functions.php file. All installations running this version are potentially vulnerable until patched.
Risk and Exploitability
The CVSS score is 5.1, indicating a moderate severity. The EPSS score is less than 1 %, implying a low probability of exploitation at the time of analysis, but the exploit is publicly available and may be used. The vulnerability is not listed in CISA’s KEV catalog. Attackers can target the endpoint remotely by sending a crafted request to the script with a malicious firstname value, causing the script to run in the victim’s browser.
OpenCVE Enrichment