Impact
A flaw exists in PHPGurukul Daily Expense Tracker System 1.1 that allows the FullName parameter in sidebar.php to be processed without proper sanitization. This results in reflected cross‑site scripting attacks that can be triggered remotely. An attacker who successfully injects malicious JavaScript can execute code in the victim’s browser session, potentially collecting credentials, hijacking the session, or performing malicious actions on behalf of the user.
Affected Systems
PHPGurukul Daily Expense Tracker System version 1.1 is affected. No additional versions are listed, and the vulnerability is tied to the sidebar.php script that processes the FullName argument.
Risk and Exploitability
CVSS 5.1 indicates a medium severity vulnerability. The EPSS score is < 1%, and the issue is not listed in CISA KEV. The attack vector is remote, and a functional exploit has already been published, making this flaw a moderate risk for exposed installations.
OpenCVE Enrichment