PT-2026-28672 · Code Projects · Exam Form Submission

Niuzzz

·

Publicado

2026-03-27

·

Atualizado

2026-03-27

·

CVE-2026-4909

CVSS v2.0

3.3

Baixa

VetorAV:N/AC:L/Au:M/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions code-projects Exam Form Submission version 1.0
Description A cross-site scripting issue exists due to the manipulation of the sname argument in the file '/admin/update s7.php'. The issue impacts an unknown function. The exploit has been publicly released and could be used for remote attacks.
Recommendations Apply updates to address the issue in version 1.0. As a temporary workaround, restrict access to the file /admin/update s7.php. Avoid using the sname parameter in the affected file /admin/update s7.php until the issue is resolved.

Exploit

Correção

XSS

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-4909

Produtos afetados

Exam Form Submission