Description
A security vulnerability has been detected in itsourcecode Payroll Management System up to 1.0. Affected is an unknown function of the file /navbar.php. Such manipulation of the argument page leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Published: 2026-04-02
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Patch Now
AI Analysis

Impact

A cross‑site scripting vulnerability exists in itsourcecode Payroll Management System via the navbar.php file. An attacker can supply a crafted page parameter that is displayed unsanitized, enabling injection of arbitrary HTML or JavaScript into the browser context. The weakness corresponds to CWE‑79 and a secondary code‑execution concern, CWE‑94, because the injected code can run with the privileges of the affected user. This flaw allows a remote actor to perform malicious actions such as defacing pages, hijacking user sessions, or stealing credentials, affecting the confidentiality, integrity, and availability of the system.

Affected Systems

The issue is present in all releases of itsourcecode Payroll Management System up through version 1.0. No later version was identified in the data, so any installation using v1.0 or earlier is potentially vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate impact, and the exploit is publicly disclosed with no restrictions on local access, making it remotely exploitable. EPSS information is unavailable, but the vulnerability is not listed in CISA’s KEV catalog. The likely attack path involves a malicious link or form that manipulates the page argument to inject code, with no special privileges required.

Generated by OpenCVE AI on April 2, 2026 at 09:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security update for itsourcecode Payroll Management System if a patch newer than version 1.0 is available.
  • If no patch is available, sanitize the page input in navbar.php and enforce an appropriate Content Security Policy to block script execution.
  • Monitor inbound traffic for suspicious page parameters and maintain up‑to‑date web application firewalls or intrusion detection systems.

Generated by OpenCVE AI on April 2, 2026 at 09:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Apr 2026 08:00:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in itsourcecode Payroll Management System up to 1.0. Affected is an unknown function of the file /navbar.php. Such manipulation of the argument page leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Title itsourcecode Payroll Management System navbar.php cross site scripting
First Time appeared Itsourcecode
Itsourcecode payroll Management System
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:itsourcecode:payroll_management_system:*:*:*:*:*:*:*:*
Vendors & Products Itsourcecode
Itsourcecode payroll Management System
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Itsourcecode Payroll Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-02T13:35:37.209Z

Reserved: 2026-04-01T12:53:28.785Z

Link: CVE-2026-5319

cve-icon Vulnrichment

Updated: 2026-04-02T13:35:32.796Z

cve-icon NVD

Status : Deferred

Published: 2026-04-02T04:16:48.883

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-5319

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-02T20:22:23Z

Weaknesses