Executive brief
A security vulnerability exists in the Simple Laundry System, a web application used for managing laundry service operations. An attacker can exploit this flaw to inject malicious scripts into the application's member modification page. If a legitimate user views the affected page, the attacker could potentially perform unauthorized actions in the user's browser or steal session information.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in code-projects Simple Laundry System 1.0 within the 'Parameter Handler' component. The flaw is located in the /modifymember.php file and stems from insufficient sanitization of the 'firstName' input parameter. A remote, unauthenticated attacker can exploit this by tricking a user into clicking a specially crafted link, leading to the execution of arbitrary JavaScript in the context of the victim's browser session. A proof-of-concept exploit has been publicly disclosed.
Affected products
- code-projects Simple Laundry System 1.0
Timeline
- 2026-04-05: disclosed: Initial vulnerability disclosure and publication of CVE-2026-5539.
- 2026-04-05: advisory: VulDB published advisory 355292.