Impact
Based on the description, the vulnerability resides in the manage_employee_allowances.php page of itsourcecode Payroll Management System. A flaw in the handling of the ID parameter allows an attacker to inject arbitrary HTML or JavaScript, enabling classic cross‑site scripting attacks. An exploited script could steal credentials, hijack user sessions, or modify displayed content.
Affected Systems
The affected vendor is itsourcecode, product Payroll Management System, version 1.0. The product is also listed under the alias angeljudesuarez:payroll_management_system. Only this version is confirmed to contain the vulnerability.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests theft or exploitation is rare. The vulnerability is not currently listed in the CISA KEV catalog, implying no known large‑scale active exploitation. The likely attack vector is remote through the public web interface, and it is inferred that no authentication is required to reach the vulnerable endpoint, so anyone with network access to the server can potentially exploit it.
OpenCVE Enrichment