Executive brief
SourceCodester Online Book Store System 1.0 is a web application used for managing book sales and inventory. A security vulnerability in the User Management Module allows an attacker with administrative privileges to inject malicious scripts into the system via the Name or Username fields. If another user views the affected profile, the script could execute in their browser, potentially leading to unauthorized actions or information disclosure within the application.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in SourceCodester Online Book Store System 1.0 within the User Management Module. The issue stems from improper neutralization of user-supplied input in the 'Name' and 'Username' arguments. A remote attacker with high privileges (e.g., an administrator) can inject arbitrary JavaScript, which is then stored on the server and executed in the context of any user who views the compromised user profile. While the attack requires high privileges and user interaction, a public exploit is available. No official patch has been confirmed at this time.
Affected products
- SourceCodester Online Book Store System 1.0
Timeline
- 2026-07-13: advisory: Initial disclosure by VulDB and NVD