PT-2026-28672 · Code Projects · Exam Form Submission
Niuzzz
·
Published
2026-03-27
·
Updated
2026-03-27
·
CVE-2026-4909
CVSS v2.0
3.3
Low
| Vector | AV:N/AC:L/Au:M/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
code-projects Exam Form Submission version 1.0
Description
A cross-site scripting issue exists due to the manipulation of the
sname argument in the file '/admin/update s7.php'. The issue impacts an unknown function. The exploit has been publicly released and could be used for remote attacks.Recommendations
Apply updates to address the issue in version 1.0.
As a temporary workaround, restrict access to the file
/admin/update s7.php.
Avoid using the sname parameter in the affected file /admin/update s7.php until the issue is resolved.Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Exam Form Submission