Description: Establishment Billing Management System contains an XSS vulnerability via the URI /admin/ajax.php?action=save_settings. Vulnerability Type: Cross Site Scripting (XSS) Vendor of Product: https://www.sourcecodester.com/php/14497/establishment-billing-management-system-using-phpmysql-source-code.html Affected Product Code Base: 1.0 Impact Escalation of Privileges: True POC: - Request payload: - Screenshot shows the alert(11) payload executing in the browser, confirming the XSS vulnerability.