Impact
The vulnerability is a cross‑site scripting flaw located in the Parameter Handler component of Simple Laundry System 1.0. By manipulating the firstName argument in /modifymember.php, an attacker can inject arbitrary JavaScript that will be executed in the context of any user visiting the affected page. The flaw can be triggered from an external network, so it is remotely exploitable. This allows an attacker to deface the interface, steal session cookies, or perform other malicious actions within the victim’s browser session.
Affected Systems
The flaw affects code‑projects Simple Laundry System version 1.0. No other product versions are listed in the CNA data.
Risk and Exploitability
The CVSS v3.1 score of 5.3 marks the vulnerability as moderate severity. No EPSS score is provided, and it is not included in the CISA KEV list, suggesting that widespread exploitation may not yet be documented. However, the existence of a published exploit indicates that attackers could potentially leverage it if the vulnerable system remains unpatched. Remote exploitation requires only the ability to send crafted input to modifymember.php, and no privileged credentials are necessary.
OpenCVE Enrichment