Impact
This vulnerability exists in the getOrderReport.php script of the SourceCodester Stock Management System. By manipulating the clientName and clientContact parameters, an attacker can cause the application to return unsanitized user input as part of the page, enabling the execution of arbitrary JavaScript on the victim’s browser. The flaw is a classic reflected XSS and is exploitable without authentication, solely through crafted HTTP requests.
Affected Systems
The affected product is SourceCodester Stock Management System version 1.0. Only the getOrderReport.php endpoint that processes the clientName and clientContact arguments is impacted. No other components are listed as vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, with no user interaction beyond sending a malicious request. The exploit has been released publicly, so attackers who discover capable clients can use it at any time.
OpenCVE Enrichment