PT-2026-27308 · Projectworlds · Lawyer Management System

Wangyiqi

·

Publicado

2026-03-24

·

Atualizado

2026-03-25

·

CVE-2026-4626

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions projectworlds Lawyer Management System version 1.0
Description A flaw exists in projectworlds Lawyer Management System 1.0. The issue is related to cross site scripting, triggered by manipulating the Description argument in the /lawyer booking.php file. This can be exploited remotely. The exploit for this issue is publicly available.
Recommendations Apply any available updates or patches for projectworlds Lawyer Management System version 1.0. As a temporary workaround, sanitize the Description input to prevent script injection. Restrict access to the /lawyer booking.php file if possible.

Exploit

Correção

Code Injection

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-4626

Produtos afetados

Lawyer Management System