Impact
The vulnerability is a cross‑site scripting flaw located in the file /index.php?page=categories. By manipulating the ID query parameter, an attacker can inject arbitrary client‑side scripts that are executed in the browsers of visitors to the affected page. The flaw is a typical reflected or stored XSS governed by CWE‑79 and may also involve code injection via query parameter, mapping to CWE‑94. The impact is limited to the victim’s browser, enabling session hijacking, phishing, or data theft, but does not compromise server‑side confidentiality or integrity.
Affected Systems
SourceCodester Pharmacy Sales and Inventory System 1.0.
Risk and Exploitability
The CVSS score of 5.3 reflects a moderate severity moderate impact with limited privileges. The exploit requires no authentication and can be performed by any remote attacker who can access the public URL. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that widespread exploitation has not yet been observed. Nevertheless, the availability of a public exploit means that a remote attacker can readily deploy the payload and observe the consequences. Overall, the risk is moderate but should not be ignored.
OpenCVE Enrichment