CVE-2026-105809: SourceCodester Simple Student Information System Profile Field register.php cross site scripting
Published Oct 6, 2026
·Updated
A vulnerability was identified in SourceCodester Simple Student Information System 1.0. This issue affects some unknown processing of the file /register.php of the component Profile Field Handler. The manipulation of the argument firstname/lastname leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly available and might be used.
Affected Software
1 affected component
Sourcecodester Simple Student Information System=1.0
Event History
Oct 6, 2026
CVE Published
via MITRE·08:15 AM
Data Sourced
via MITRE·08:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require an authenticated account or user interaction?
No privileges are required by the CVSS vector, but exploitation requires user interaction. The attack can be initiated remotely.
2
Which inputs should be prioritized for review and filtering?
The affected processing is in /register.php within the Profile Field Handler. The firstname and lastname arguments are identified as the XSS injection points.
3
Is exploit code available?
Yes. A public exploit is available and may be used.