Impact
The flaw resides in the /delstaffinfo.php script of code‑projects Simple Laundry System. Manipulation of the userid argument triggers a reflected cross‑site scripting vulnerability. When an attacker delivers a crafted request to the vulnerable endpoint, the browser will execute the injected JavaScript in the context of the web application, potentially exposing sensitive data, defacing the interface, or redirecting users to malicious sites.
Affected Systems
This vulnerability affects only code‑projects Simple Laundry System version 1.0. No other versions or components are listed as affected. The attack vector is a remote request to the /delstaffinfo.php page, with the userid parameter containing malicious payload.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity. An EPSS score of less than 1 % reflects a low likelihood of widespread exploitation at present, and the flaw is not in the CISA KEV catalog. The description explicitly states that the attack may be launched remotely, meaning an attacker only needs to construct a malicious URL; no privileged access or additional conditions are required.
OpenCVE Enrichment