Impact
The vulnerability is a reflected cross‑site scripting flaw in the Simple Laundry System 1.0 component that processes the userid argument in /modmemberinfo.php. By inserting malicious HTML or JavaScript into the userid parameter, a remote attacker can cause the victim’s browser to execute the payload, potentially allowing defacement, cookie theft, or further attacks against the user.
Affected Systems
The flaw exists in the code‑projects Simple Laundry System 1.0. No other versions are confirmed to be impacted, but any instance of this legacy application that has not applied the vendor’s fix is vulnerable.
Risk and Exploitability
With a CVSS score of 5.3 the vulnerability is considered moderate. The exploit can be triggered from any Internet‑connected client with no authentication, and the vulnerability has already been made public. Although it is not listed in the KEV catalog and no EPSS score is available, the availability of the exploit and the remote nature of the attack vector raise the risk level for environments that expose this application to untrusted users.
OpenCVE Enrichment