Code-Projects E-Commerce Website Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in Code-Projects E-Commerce Website version 1.0. The issue resides in the file '/pages/supplier_add.php', where user-supplied input in the 'supp_name' and 'supp_address' fields is not properly sanitized before being stored. This allows for the injection of malicious scripts that are executed when other users view the affected page. The vulnerability can be exploited remotely, and a public exploit is available.

Impact

Exploitation of this vulnerability allows for the injection of persistent malicious JavaScript that executes in the context of users viewing the affected page. This could lead to session hijacking, account takeover, and theft of sensitive information.

Reproduction

To reproduce this vulnerability, navigate to the 'supplier_add.php' page and locate the input fields for 'supp_name' and 'supp_address'. Inject a script payload, such as an alert script, into these fields and submit the form. The injected script will execute when the page is viewed by other users.

Added: Oct 27, 2025, 11:19 PM
Updated: Oct 27, 2025, 11:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.4
exploitability
7.7
remediation
0.0
relevance
0.8
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.