Description
A vulnerability was determined in itsourcecode Payroll Management System 1.0. Affected is an unknown function of the file /manage_employee_allowances.php. This manipulation of the argument ID causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Published: 2026-03-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Patch ASAP
AI Analysis

Impact

Based on the description, the vulnerability resides in the manage_employee_allowances.php page of itsourcecode Payroll Management System. A flaw in the handling of the ID parameter allows an attacker to inject arbitrary HTML or JavaScript, enabling classic cross‑site scripting attacks. An exploited script could steal credentials, hijack user sessions, or modify displayed content.

Affected Systems

The affected vendor is itsourcecode, product Payroll Management System, version 1.0. The product is also listed under the alias angeljudesuarez:payroll_management_system. Only this version is confirmed to contain the vulnerability.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests theft or exploitation is rare. The vulnerability is not currently listed in the CISA KEV catalog, implying no known large‑scale active exploitation. The likely attack vector is remote through the public web interface, and it is inferred that no authentication is required to reach the vulnerable endpoint, so anyone with network access to the server can potentially exploit it.

Generated by OpenCVE AI on April 17, 2026 at 11:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the patched version of itsourcecode Payroll Management System once it becomes available.
  • Apply input sanitization and output encoding for the ID parameter in manage_employee_allowances.php, ensuring proper contextual escaping such as htmlspecialchars for HTML or JSON encoding for JavaScript contexts.
  • Restrict access to the payroll management console by implementing IP filtering or a VPN requirement so that only trusted administrators can reach the management pages.
  • Deploy a web application firewall rule set that blocks typical XSS payloads for the affected endpoint.

Generated by OpenCVE AI on April 17, 2026 at 11:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 10 Mar 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Mar 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Angeljudesuarez
Angeljudesuarez payroll Management System
CPEs cpe:2.3:a:angeljudesuarez:payroll_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Angeljudesuarez
Angeljudesuarez payroll Management System

Mon, 09 Mar 2026 09:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in itsourcecode Payroll Management System 1.0. Affected is an unknown function of the file /manage_employee_allowances.php. This manipulation of the argument ID causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Title itsourcecode Payroll Management System manage_employee_allowances.php cross site scripting
First Time appeared Itsourcecode
Itsourcecode payroll Management System
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:itsourcecode:payroll_management_system:*:*:*:*:*:*:*:*
Vendors & Products Itsourcecode
Itsourcecode payroll Management System
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Angeljudesuarez Payroll Management System
Itsourcecode Payroll Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-03-10T15:59:26.966Z

Reserved: 2026-03-08T16:24:34.768Z

Link: CVE-2026-3812

cve-icon Vulnrichment

Updated: 2026-03-10T15:59:23.729Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-09T09:16:03.400

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-3812

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T12:00:11Z

Weaknesses