Impact
A reflected Cross‑Site Scripting vulnerability exists in the view_supplier.php component of SourceCodester Sales and Inventory System 1.0. The application does not sanitize the 'limit' parameter, allowing remote attackers to embed arbitrary web script or HTML into a crafted URL. When a user loads the page, the injected code executes in their browser.
Affected Systems
The affected product is SourceCodester Sales and Inventory System version 1.0. No other versions or products are mentioned, and the version is identified by the provided CPE.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity, while the EPSS score below 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a remote web request containing a malicious payload in the 'limit' parameter; a victim who accesses the crafted link will have the script executed in their browser. No additional prerequisites are required beyond user interaction with the URL.
OpenCVE Enrichment