Description
A security vulnerability has been detected in code-projects Accounting System 1.0. Impacted is an unknown function of the file /my_account/add_costumer.php of the component Web Application Interface. Such manipulation of the argument costumer_name leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
Problem types
Product status
Timeline
| 2026-03-25: | Advisory disclosed |
| 2026-03-25: | VulDB entry created |
| 2026-03-25: | VulDB entry last update |
Credits
AhmadMarzook (VulDB User)
References
vuldb.com/?id.353139 (VDB-353139 | code-projects Accounting System Web Application add_costumer.php cross site scripting)
vuldb.com/?ctiid.353139 (VDB-353139 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.775859 (Submit #775859 | code-projects Accounting System In PHP 1.0 Cross Site Scripting)
github.com/... Scripting (XSS) in costumer_name Parameter.md
code-projects.org/