Cross Site Scripting Vulnerability in Code-Projects Exam Form Submission 1.0
CVE-2026-4576
Key Information:
- Vendor
Code-projects
- Status
- Vendor
- CVE Published:
- 23 March 2026
Badges
What is CVE-2026-4576?
A vulnerability in the code-projects Exam Form Submission software has been identified, specifically within the file /admin/update_s5.php. The flaw allows remote attackers to manipulate the 'sname' parameter, leading to Cross Site Scripting (XSS) attacks. This exploitation can potentially compromise user sessions and data integrity, as the malicious scripts may be executed in the context of a victim's browser. Public disclosure of this vulnerability implies an increased risk, emphasizing the need for prompt security assessments and remediation.
Affected Version(s)
Exam Form Submission 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
