Junglewise Threat Intelligence

CVE-2026-5541: code-projects Simple Laundry System XSS in modmemberinfo.php

CVE-2026-5541 · Severity: medium · CVSS 4.3 · Published 2026-04-05

Technologies: Code-Projects Simple Laundry System. Vendors: Code-Projects.

Executive brief

A vulnerability exists in the Simple Laundry System, a web application used for managing laundry service operations. An attacker can trick a user into clicking a malicious link, allowing the attacker to execute unauthorized scripts in the user's browser. This could lead to the theft of session information or unauthorized actions performed on behalf of the user.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in code-projects Simple Laundry System 1.0. The issue is located in the 'Parameter Handler' component within the /modmemberinfo.php file. Specifically, the application fails to properly sanitize the 'userid' argument before rendering it back to the user. A remote attacker can exploit this by crafting a malicious URL that, when visited by a victim, executes arbitrary JavaScript in the context of the victim's browser session. A public exploit (Proof of Concept) has been disclosed.

Affected products

  • code-projects Simple Laundry System 1.0

Timeline

  • 2026-04-05: disclosed: Initial disclosure and publication of the CVE record.
  • 2026-04-05: advisory: VulDB published the vulnerability details.

References

Related threats