Junglewise Threat Intelligence

CVE-2026-10301: itsourcecode Fees Management System XSS in index.php

CVE-2026-10301 · Severity: medium · CVSS 4.3 · Published 2026-06-02

Technologies: Itsourcecode Fees Management System. Vendors: Itsourcecode.

Executive brief

A vulnerability exists in the itsourcecode Fees Management System, a software used for managing educational or service fees. An attacker can trick a user into clicking a malicious link, allowing the attacker to execute unauthorized scripts in the user's browser. This could lead to the theft of login session information or the performance of unauthorized actions on behalf of the user.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in itsourcecode Fees Management System 1.0. The issue is located in the index.php file, where the 'page' URL parameter is reflected into the page output without sufficient sanitization or encoding. A remote, unauthenticated attacker can exploit this by crafting a malicious URL and enticing a user to visit it. Successful exploitation allows the execution of arbitrary JavaScript in the victim's browser context, which can be used for session hijacking, cookie theft, or unauthorized redirection. The exploit is currently public.

Affected products

  • itsourcecode Fees Management System 1.0

Timeline

  • 2026-05-13: disclosed: Initial vulnerability report on GitHub
  • 2026-06-02: advisory: CVE published and added to NVD

References

Related threats