CyberRota Analysis
AI-GeneratedThe SourceCodester Stock Management System 1.0 is vulnerable to cross-site scripting (XSS) due to improper handling of input in the /php_action/getOrderReport.php file, specifically through the clientName and clientContact parameters. This vulnerability allows remote attackers to execute malicious scripts in the context of a user's session, potentially leading to data theft or session hijacking. Organizations using this system should prioritize patching or mitigating this vulnerability to protect against potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability was found in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of the file /php_action/getOrderReport.php. Performing a manipulation of the argument clientName/clientContact results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used.