Description
A flaw has been found in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /modifymember.php of the component Parameter Handler. This manipulation of the argument firstName causes cross site scripting. The attack can be initiated remotely. The exploit has been published and may be used.
Problem types
Product status
Timeline
| 2026-04-04: | Advisory disclosed |
| 2026-04-04: | VulDB entry created |
| 2026-04-04: | VulDB entry last update |
Credits
Weining Xiao (VulDB User)
References
vuldb.com/vuln/355292 (VDB-355292 | code-projects Simple Laundry System Parameter modifymember.php cross site scripting)
vuldb.com/vuln/355292/cti (VDB-355292 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/782221 (Submit #782221 | code-projects Simple Laundry System V1.0 cross site scripting)
github.com/boyslikesports/vul-web/issues/5
code-projects.org/