## Critical Vulnerability Information - **Title**: SourceCodester Student Study Center Desk Management System 1.0 Cross Site Scripting in "username" parameter - **Description**: - Related code file: `/sections/classes/Users.php?f=save` - XSS Parameter: `username` - In POST requests, the `username` parameter is vulnerable to Cross-Site Scripting (XSS). - Example Payload: ```html print(); ``` - **Report Link**: https://reports.kunull.vercel.app/CVE%20research/student-study-center-desk-management-system-xss-username - **Source**: https://www.sourcecodester.com/php/16298/student-study-center-desk-management-system-using-php-cop-and-mysql-db-free-source-code - **Submitter**: Anonymous User - **Submission Date**: 2024-07-15 03:57 PM (11 months ago) - **Review Date**: 2024-07-16 09:41 PM (1 day after submission) - **Status**: Pending - **VulDB Entry**: [SourceCodester Student Study Center Desk Management System 1.0 HTTP POST Request Users.php?f=save]