CVE-2026-0586: code-projects Online Product Reservation System prod.php cross site scripting
A vulnerability was detected in code-projects Online Product Reservation System 1.0. The affected element is an unknown function of the file handgunner-administrator/prod.php. Performing a manipulation of the argument cat results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0586?
CVE-2026-0586 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2026-0586?
To fix CVE-2026-0586, sanitize and validate user input for the 'cat' parameter in the handgunner-administrator/prod.php file.
What systems are affected by CVE-2026-0586?
CVE-2026-0586 affects the Code-projects Online Product Reservation System version 1.0.
What type of vulnerability is CVE-2026-0586?
CVE-2026-0586 is a cross-site scripting (XSS) vulnerability.
Can CVE-2026-0586 be exploited remotely?
Yes, CVE-2026-0586 can be exploited remotely by manipulating the 'cat' argument in a web request.