Impact
A reflected Cross‑Site Scripting flaw exists in the SourceCodester Sales and Inventory System 1.0. The flaw is triggered through the uncensored 'msg' parameter in add_stock.php, enabling a remote attacker to embed arbitrary JavaScript or HTML into the page. An exploited victim’s browser would execute the injected code, allowing session hijacking, data theft, or site defacement.
Affected Systems
SourceCodester Sales and Inventory System version 1.0 is affected. The vulnerability is located in the add_stock.php module that accepts a 'msg' query string.
Risk and Exploitability
The CVSS score of 9.3 reflects a high risk; the EPSS score is below 1% and the flaw is not yet listed in the KEV catalog. Exploitation requires an attacker to craft a malicious URL that includes the injected payload in the 'msg' parameter and deliver it to a victim who visits the link. No authentication or privileged access is needed to trigger the flaw.
OpenCVE Enrichment