Glamour Salon Management System Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in the Glamour Salon Management System version 1, developed by Hiruna Gallage. The issue is located in the 'blog-details.php' file, specifically on line 65. This vulnerability allows remote attackers to inject arbitrary web scripts or HTML into the blog comment section, which is not properly sanitized before being displayed. As a result, malicious JavaScript can be executed in the browsers of users who view the affected page.

Impact

Exploitation of this vulnerability allows attackers to execute malicious JavaScript in the context of the victim's browser. This could lead to impersonating the user, capturing login credentials, performing actions on behalf of the user, or injecting malicious functionality into the website.

Reproduction

To reproduce this vulnerability, navigate to the blog comment section of the Glamour Salon Management System. Submit a comment containing a script tag, such as one that triggers a JavaScript alert. After posting the comment, refresh the page to see the injected script execute in the browser.

Remediation

To address this vulnerability, input sanitization should be implemented in the 'blog-details.php' file. Using PHP's 'htmlspecialchars()' function can encode special characters into HTML entities, preventing the execution of injected scripts.

Added: Oct 30, 2025, 4:00 PM
Updated: Oct 30, 2025, 4:00 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
7.7
remediation
0.0
relevance
0.8
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.