A vulnerability was found in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of the file /php_action/getOrderReport.php. Performing a manipulation of the argument clientName/clientContact results in cross site scripting.
It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Attack Parameters
Impact Assessment
CVSS Vector v4.0