CVE-2023-3184

LOW

SourceCodester Sales Tracker Management System 1.0 - XSS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-3184. PoCs published by AFFAN AHMED.

AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Sales Tracker Management System v1.0, where malicious payloads can be injected into user fields (firstname, middlename, lastname, username) and executed when viewed by other users.

Description

A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /classes/Users.php?f=save. The manipulation of the argument firstname/middlename/lastname/username leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-231164.

Exploits (1)

exploitdb WORKING POC VERIFIED
by AFFAN AHMED · textwebappsphp
https://www.exploit-db.com/exploits/51513

This exploit demonstrates a stored XSS vulnerability in Sales Tracker Management System v1.0, where malicious payloads can be injected into user fields (firstname, middlename, lastname, username) and executed when viewed by other users.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Sales Tracker Management System v1.0
Auth required
Prerequisites: Admin credentials · Access to the user creation form
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4

Scores

CVSS v3 2.4
EPSS 0.0226
EPSS Percentile 80.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
sales_tracker_management_system_project/sales_tracker_management_system 1.0
Published Jun 09, 2023
Tracked Since Feb 18, 2026