Impact
The flaw is in the Settings Update Endpoint’s save-settings.php where the arguments site_name and site_desc are not properly validated or sanitized before being reflected in the web page. An attacker can inject malicious scripts that execute in the victim’s browser, which can lead to session hijacking, defacement, or further client‑side compromise. The vulnerability is classified as Type 79 (XSS) and also involves potential code injection (Type 94).
Affected Systems
The affected product is SourceCodester Simple Traffic Offense System version 1.0. No other vendors or product versions are listed. The attack surface is limited to the save‑settings.php upload interface, but once injected, the payload runs in the context of any user who views the affected page.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact. The EPSS score is not available, but the vulnerability is publicly disclosed and remote exploitation is possible, meaning an attacker can plant a script by送ting a crafted POST request to the endpoint without any special local privileges. The flaw is not yet cataloged in CISA KEV, so no known active exploitation campaigns have been reported. Nonetheless, due to the widespread use of XSS for credential theft and phishing, the risk to users that rely on the affected system is significant and should be mitigated promptly.
OpenCVE Enrichment