Impact
A flaw was discovered in SourceCodester Queue Management System 1.0 that allows an attacker to inject arbitrary scripting content through the Name parameter in the add_customer.php endpoint. This injection can lead to cross‑site scripting, enabling malicious scripts to run in the context of any user who views the affected page. Based on the description, it is inferred that the attack can be carried out remotely by sending a crafted HTTP request to the publicly accessible add_customer.php endpoint, but no authentication requirement is mentioned. The vulnerability is classified under CWE-79 and CWE-94.
Affected Systems
The affected product is SourceCodester's Queue Management System, version 1.0. No other versions or components are known to be impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity. No EPSS score is available, so the current exploitation probability cannot be quantified, and the vulnerability is not listed in CISA KEV. The attack vector is remote, as the exploit can be triggered via a crafted HTTP request to the publicly accessible add_customer.php endpoint. The published exploit suggests that malicious payloads can be delivered without authentication, making this risk relevant for publicly exposed deployments.
OpenCVE Enrichment