Cross Site Scripting Vulnerability in SourceCodester Online Book Store System
CVE-2026-19904
4.8MEDIUM
Key Information:
- Vendor
Sourcecodester
- Status
- Vendor
- CVE Published:
- 15 August 2026
What is CVE-2026-19904?
A vulnerability has been discovered in the SourceCodester Online Book Store System 1.0, specifically within the System Settings Module located in /admin/index.php?page=site_settings. This flaw allows for cross site scripting (XSS) exploits to occur. Attackers can manipulate unknown code in this component, enabling remote execution of harmful scripts. Given the public nature of the exploit, it poses a risk to users and requires prompt attention.
Affected Version(s)
Online Book Store System 1.0
