A Cross-site Scripting (XSS) vulnerability in managerecipient.php of Sourcecodester Toll Tax Management System 1.0 allows remote authenticated users to inject arbitrary web scripts via the "owner" input field.
Sourcecodester Toll Tax Management System v1 is vulnerable to SQL Injection.
Toll-tax-management-system v1.0 is vulnerable to Cross Site Scripting (XSS) via /ttms/classes/Master.php?f=saverecipient, vehiclename.
In Toll Tax Management System 1.0, the id parameter appears to be vulnerable to SQL injection attacks.