PT-2026-28672 · Code Projects · Exam Form Submission

Niuzzz

·

Published

2026-03-27

·

Updated

2026-03-27

·

CVE-2026-4909

CVSS v2.0

3.3

Low

VectorAV:N/AC:L/Au:M/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions code-projects Exam Form Submission version 1.0
Description A cross-site scripting issue exists due to the manipulation of the sname argument in the file '/admin/update s7.php'. The issue impacts an unknown function. The exploit has been publicly released and could be used for remote attacks.
Recommendations Apply updates to address the issue in version 1.0. As a temporary workaround, restrict access to the file /admin/update s7.php. Avoid using the sname parameter in the affected file /admin/update s7.php until the issue is resolved.

Exploit

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-4909

Affected Products

Exam Form Submission