Cross Site Scripting
Cross Site Scripting vulnerability in /php-lms/classes/Users.php?f=save in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the firstname, middlename, lastname parameters.
Path URL: /php-lms/classes/Users.php?f=save
Parameters: firstname, middlename, lastname
Input payload <script>alert(123)</script>
into firstname parameter and save it.