Cross Site Scripting Vulnerability in Projectwolds Online Attendance System
CVE-2026-86226
Key Information:
- Vendor
Projectwolds
- Status
- Vendor
- CVE Published:
- 6 September 2026
Badges
What is CVE-2026-86226?
A serious security flaw has been identified in the Projectwolds Online Attendance System version 1.0. The vulnerability exists in an unknown function within the profile.php file, where manipulating the 'email' argument leads to cross site scripting attacks. This flaw can be exploited remotely, potentially compromising user data and allowing attackers to execute malicious scripts. The exploit has been made public, raising concerns about the system's security integrity and the safety of user interactions.
Affected Version(s)
Online Attendance System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
