Junglewise Threat Intelligence

CVE-2026-30526: A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Zoo Management System v1.0. The vulnerability is located in th

CVE-2026-30526 · Severity: medium · CVSS 6.1 · Published 2026-04-01

Vendors: SourceCodester.

Executive brief

SourceCodester Zoo Management System is a web application used for managing zoo operations and animal records. A security flaw in its login page allows attackers to send malicious links to users that, when clicked, execute unauthorized scripts in the victim's browser. This could lead to the theft of login credentials, session hijacking, or the display of fraudulent content to legitimate users.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the login component of SourceCodester Zoo Management System v1.0. The application fails to properly sanitize or HTML-encode the 'msg' GET parameter before reflecting it back to the user's browser. An unauthenticated remote attacker can exploit this by crafting a malicious URL containing a JavaScript payload (e.g., using the 'onerror' attribute of an 'img' tag). If a user visits the crafted link, the script executes in the context of their session, potentially allowing for session cookie theft, DOM manipulation, or redirection to malicious sites.

Affected products

  • SourceCodester Zoo Management System 1.0

Timeline

  • 2026-04-01: disclosed: Initial disclosure and CVE assignment
  • 2026-04-01: advisory: NVD publication date

References