Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-90795 1 Itsourcecode 1 Loan Management System 2026-09-15 4.3 Medium
A vulnerability was determined in itsourcecode Loan Management System 1.0. The impacted element is an unknown function of the file navbar.php. Executing a manipulation of the argument page can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2024-48415 2 Itsourcecode, Razormist 2 Loan Management System, Loan Management System 2024-11-26 4.6 Medium
itsourcecode Loan Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the lastname, firstname, middlename, address, contact_no, email and tax_id parameters in new borrowers functionality on the Borrowers page.