Cross Site Scripting Vulnerability in SourceCodester Student Result Management System
CVE-2026-104612
5.3MEDIUM
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 2 October 2026
What is CVE-2026-104612?
A vulnerability exists in the SourceCodester Student Result Management System version 1.0, specifically within the Announcement Module's new_announcement.php file. This weakness allows remote attackers to execute cross site scripting (XSS) attacks by manipulating the 'title' or 'announcement' arguments. The publicly disclosed nature of this exploit poses a risk for users who may be susceptible to such attacks, potentially compromising user data and system integrity.
Affected Version(s)
Student Result Management System 1.0
