Cross-Site Scripting Affecting SourceCodester Smart Attendance System
CVE-2026-95957
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 23 September 2026
Badges
What is CVE-2026-95957?
A vulnerability exists in the SourceCodester Smart Attendance System with QR Code Scanner 1.0, specifically in the function prepend of student_signup.php within the Self-Registration component. This flaw allows for manipulation of the full_name argument, leading to potential cross-site scripting attacks. Attackers can exploit this vulnerability remotely, exposing users to various risks. The exploit details have been disclosed publicly, emphasizing the urgency for affected users to implement necessary security measures.
Affected Version(s)
Smart Attendance System with QR Code Scanner 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
