Impact
The vulnerability is a reflected cross‑site scripting flaw in the 'lname' parameter of the UpdateUserProfile.php file of code‑projects Task Management System version 1.0. An attacker can inject malicious script by manipulating the lname argument, causing the browser to execute the code when a victim’s browser renders the profile page. This leads to compromise of confidentiality, integrity, and potentially session hijacking for the targeted user.
Affected Systems
The affected product is code‑projects Task Management System version 1.0. It is an open‑source task management application. Users running version 1.0 who have administrative access to the user profile update feature are directly affected.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. No EPSS score is publicly available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation activity. Nevertheless, the exploit is publicly available and can be launched remotely by supplying a crafted lname value. Attackers could inject scripts that run in the victim’s browser, potentially stealing session cookies or executing arbitrary code within the context of the application.
OpenCVE Enrichment