CVE-2026-90795: itsourcecode Loan Management System navbar.php cross site scripting
A vulnerability was determined in itsourcecode Loan Management System 1.0. The impacted element is an unknown function of the file navbar.php. Executing a manipulation of the argument page can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attack can be launched remotely and does not require privileges, but it requires user interaction. An attacker would need to cause a user to interact with a crafted request containing a manipulated page argument.
Is there public exploit information available?
Yes. The exploit has been publicly disclosed and may be used by attackers.
Which installation is identified as affected?
The affected product is itsourcecode Loan Management System version 1.0. The vulnerable functionality is associated with navbar.php and its page argument.