Impact
SourceCodester Loan Management System 1.0 contains a reflected cross‑site scripting vulnerability in the index.php file. Manipulating the page query argument causes arbitrary script code to be injected and executed in the victim’s browser. This flaw, categorized as CWE‑79 and linked to CWE‑94, can enable attackers to deface the site, steal session cookies, or inject malicious content. The CVE description confirms that the exploit is remote and publicly available.
Affected Systems
The vulnerability affects the SourceCodester Loan Management System, version 1.0, as disclosed by SourceCodester. No other product versions or vendors are listed. Users or organizations running this specific release are at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1 % denotes a very low but non‑zero probability of exploitation. The flaw is not currently listed in the CISA KEV catalog. Attackers can reach the vulnerable parameter through any user‑accessible web request, making the attack readily feasible without special prerequisites.
OpenCVE Enrichment