itsourcecode Online Petshop Management System Stored Cross-Site Scripting Vulnerability in Admin Dashboard

Vulnerability

A stored cross-site scripting vulnerability has been identified in the itsourcecode Online Petshop Management System version 1.0. The issue arises in the Admin Dashboard component, specifically within the availableframe.php file. The vulnerability is triggered by manipulating the name and address fields in the order submission form. Malicious scripts injected into these fields are saved in the database and later executed when the admin views the orders, allowing attackers to run arbitrary JavaScript in the admin's browser. This could lead to cookie theft, unauthorized actions on behalf of the admin, or alterations to the dashboard content.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts execute automatically in the context of the admin user without any additional interaction required.

Reproduction

To reproduce this vulnerability, submit an order through the availableframe.php order form, injecting a script payload into the name and address fields. Once the order is submitted, log into the admin dashboard and view the new order. The injected script will execute immediately in the admin's browser, demonstrating the stored XSS vulnerability.

Added: Sep 18, 2025, 2:19 AM
Updated: Sep 18, 2025, 2:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
7.7
remediation
0.0
relevance
0.5
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.