Impact
A cross‑site scripting vulnerability exists in itsourcecode Payroll Management System via the navbar.php file. An attacker can supply a crafted page parameter that is displayed unsanitized, enabling injection of arbitrary HTML or JavaScript into the browser context. The weakness corresponds to CWE‑79 and a secondary code‑execution concern, CWE‑94, because the injected code can run with the privileges of the affected user. This flaw allows a remote actor to perform malicious actions such as defacing pages, hijacking user sessions, or stealing credentials, affecting the confidentiality, integrity, and availability of the system.
Affected Systems
The issue is present in all releases of itsourcecode Payroll Management System up through version 1.0. No later version was identified in the data, so any installation using v1.0 or earlier is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact, and the exploit is publicly disclosed with no restrictions on local access, making it remotely exploitable. EPSS information is unavailable, but the vulnerability is not listed in CISA’s KEV catalog. The likely attack path involves a malicious link or form that manipulates the page argument to inject code, with no special privileges required.
OpenCVE Enrichment