PT-2026-46223 · Itsourcecode · Fleet Management System
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
itsourcecode Fees Management System versions prior to 1.1
Description
A cross-site scripting issue exists in the
/navbar.php file. Remote attackers can exploit this by manipulating the page argument, allowing the execution of malicious scripts in the victim's browser.Recommendations
Update to a version later than 1.0.
As a temporary workaround, restrict access to the
/navbar.php file or sanitize the page argument to minimize the risk of exploitation.Exploit
Fix
Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fleet Management System