Impact
A reflected XSS flaw in the view_payments.php page permits attackers to inject arbitrary JavaScript or HTML through the unsanitized limit query parameter. The injected payload can execute in the victim’s browser, enabling session hijacking, credential theft, and defacement of the application, corresponding to CWE‑79.
Affected Systems
The vulnerability affects SourceCodester Sales and Inventory System version 1.0, as identified by the provided CPE string.
Risk and Exploitability
With a CVSS score of 6.1 the flaw presents moderate severity, while the EPSS score of less than 1 % indicates a low likelihood of current exploitation. The bug is not listed in the CISA KEV catalog. Likely exploitation requires a remote attacker to craft a malicious URL containing the limit parameter and lure or force a legitimate user to visit it, resulting in the execution of the injected script.
OpenCVE Enrichment