Description
A vulnerability was detected in SourceCodester Loan Management System 1.0. Affected by this issue is some unknown functionality of the file /index.php. Performing a manipulation of the argument page results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Published: 2026-03-08
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

SourceCodester Loan Management System 1.0 contains a reflected cross‑site scripting vulnerability in the index.php file. Manipulating the page query argument causes arbitrary script code to be injected and executed in the victim’s browser. This flaw, categorized as CWE‑79 and linked to CWE‑94, can enable attackers to deface the site, steal session cookies, or inject malicious content. The CVE description confirms that the exploit is remote and publicly available.

Affected Systems

The vulnerability affects the SourceCodester Loan Management System, version 1.0, as disclosed by SourceCodester. No other product versions or vendors are listed. Users or organizations running this specific release are at risk.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1 % denotes a very low but non‑zero probability of exploitation. The flaw is not currently listed in the CISA KEV catalog. Attackers can reach the vulnerable parameter through any user‑accessible web request, making the attack readily feasible without special prerequisites.

Generated by OpenCVE AI on April 16, 2026 at 10:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a patched version of the SourceCodester Loan Management System that removes the unsanitized page parameter.
  • Implement server‑side validation or output‑encoding for the page argument so that any injected script is neutralized.
  • If a patch is unavailable, disable or strictly whitelist the page parameter to prevent it from influencing page rendering.

Generated by OpenCVE AI on April 16, 2026 at 10:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 10 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Mar 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Oretnom23
Oretnom23 loan Management System
CPEs cpe:2.3:a:oretnom23:loan_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Oretnom23
Oretnom23 loan Management System

Mon, 09 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Sourcecodester
Sourcecodester loan Management System
Vendors & Products Sourcecodester
Sourcecodester loan Management System

Sun, 08 Mar 2026 04:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in SourceCodester Loan Management System 1.0. Affected by this issue is some unknown functionality of the file /index.php. Performing a manipulation of the argument page results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Title SourceCodester Loan Management System index.php cross site scripting
Weaknesses CWE-79
CWE-94
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Oretnom23 Loan Management System
Sourcecodester Loan Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-03-10T13:59:23.107Z

Reserved: 2026-03-07T08:50:14.421Z

Link: CVE-2026-3702

cve-icon Vulnrichment

Updated: 2026-03-10T13:59:16.285Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-08T05:16:28.837

Modified: 2026-03-09T16:36:37.543

Link: CVE-2026-3702

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T10:45:26Z

Weaknesses