Impact
The vulnerability resides in Reg.php of the Record Management System and allows an attacker to inject arbitrary JavaScript through manipulation of the desc parameter. This stored cross‑site scripting flaw (CWE‑79) enables the execution of malicious script in the context of any user who views the stored data. Additionally, the flaw may involve code injection (CWE‑94), potentially expanding the impact beyond script execution.
Affected Systems
The affected product is code‑projects Record Management System version 1.0. It is relevant to installations that use the main/reg.php registration function and accept a desc argument. Any user interacting with this registration path is potentially exposed.
Risk and Exploitability
The CVSS score of 5.3 places the issue in the moderate risk range, and the vulnerability is not listed in the KEV catalog, with an EPSS score of less than 1%. The flaw can be triggered remotely by supplying a malicious desc value via a URL or form submission. Because it is stored, the injected payload remains in the system and will run for all subsequent users who view the impacted data. The public availability of an exploit indicates that an attacker could use existing tools without additional development.
OpenCVE Enrichment