Impact
A reflected cross‑site scripting vulnerability exists in the Loan Management System unknown internal function that uses the ‘page’ query argument without proper sanitization. By supplying specially crafted input for that argument, an attacker can inject arbitrary client‑side script that will execute in the browser of any user who views the vulnerable page. This allows theft of session cookies, defacement, or redirection to malicious sites.
Affected Systems
The affected product is itsourcecode Loan Management System version 1.0. The CNA lists only this version; no other versions or detailed patch information are available. The vulnerability applies to installations that expose the navbar.php endpoint to external traffic.
Risk and Exploitability
The CVSS base score is 5.3, indicating a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The vulnerability can be exploited remotely via a URL such as 'navbar.php?page=<script>'. Because it is a reflected XSS, the attacker does not need prior authentication, but the victim must visit the crafted link. No prerequisite system state is required beyond the public exposure of the page parameter.
OpenCVE Enrichment