Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_purchase.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SourceCodester Sales and Inventory System 安全漏洞
Vulnerability Description
SourceCodester Sales and Inventory System是SourceCodester开源的一个销售和库存系统。 SourceCodester Sales and Inventory System 1.0版本存在安全漏洞,该漏洞源于add_purchase.php文件中参数msg输入清理不当,可能导致反射型跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A