Cross-Site Scripting Vulnerability in SourceCodester Simple Traffic Offense System
CVE-2026-86294
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 7 September 2026
Badges
What is CVE-2026-86294?
A cross-site scripting (XSS) vulnerability exists in the SourceCodester Simple Traffic Offense System 1.0. The issue arises from improper handling of input in the save-settings.php file of the Settings Update Endpoint. By manipulating the parameters site_name or site_desc, an attacker could inject malicious scripts, enabling remote exploitation. This flaw poses a risk as it allows attackers to execute arbitrary JavaScript in the context of the user's browser. Immediate attention and patching of this vulnerability are strongly recommended to safeguard user data.
Affected Version(s)
Simple Traffic Offense System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
