Impact
The SourceCodester Stock Management System contains a reflected XSS flaw (CWE‑79) that arises when the clientName and clientContact arguments are concatenated into a response without proper sanitization. Additionally, the manipulation of these parameters can lead to arbitrary code execution via PHP injection (CWE‑94). An attacker can supply crafted input containing script tags or malicious PHP code, which the application will embed in the rendered page. This code runs in the victim’s browser or server context, potentially stealing session credentials, defacing the interface, or redirecting to malicious sites. The impact is an arbitrary script or code execution within the web application, compromising confidentiality, integrity, and trustworthiness of user data.
Affected Systems
The vulnerability exists in SourceCodester Stock Management System version 1.0. Users running this release without applying any vendor‑supplied fix or update are exposed.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity risk, and the EPSS score is not available, so the exact likelihood of exploitation is uncertain. The vulnerability has been publicly disclosed and can be triggered remotely without any authentication. Although the vulnerability is not listed in the CISA KEV catalog, the publicly available exploit code means the risk to exposed installations is moderate and should be mitigated promptly.
OpenCVE Enrichment