Impact
An XSS flaw exists in the /admin/sumit_form.php page of the code-projects Online Shopping System. By manipulating the Success parameter, an attacker can inject arbitrary script payloads that execute in the context of the administrator’s browser session. The vulnerability could be used to steal session cookies, deface the admin interface, or redirect users to malicious sites. The damage largely depends on the privileges of the victim and the information the attacker can glean from the browser context.
Affected Systems
The vulnerable product is code-projects Online Shopping System version 1.0. The flaw resides in the admin/sumit_form.php file and targets the Success argument. No other affected products or versions are listed.
Risk and Exploitability
The vulnerability has a CVSS score of 5.3, indicating a moderate severity. The EPSS score is not available, providing insufficient data on current exploitation likelihood, but the vulnerability has been publicly disclosed and can be launched from an external network. It is not included in the CISA KEV list. Attackers can remotely inject payloads without needing authenticated access, making this a likely target for exploitation by scripts or bots.
OpenCVE Enrichment