CVE-2026-2156: code-projects Online Student Management System Announcement Management index.php cross site scripting
A weakness has been identified in code-projects Online Student Management System 1.0. The impacted element is an unknown function of the file /admin/announcement/index.php?view=add of the component Announcement Management Module. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2156?
CVE-2026-2156 has a medium severity rating due to the potential for cross-site scripting vulnerabilities.
How do I fix CVE-2026-2156?
To fix CVE-2026-2156, sanitize and validate user input in the affected /admin/announcement/index.php component.
What are the potential impacts of CVE-2026-2156?
The potential impacts of CVE-2026-2156 include unauthorized access to sensitive data and spreading malicious code.
Which version of the Online Student Management System is affected by CVE-2026-2156?
CVE-2026-2156 affects version 1.0 of the Online Student Management System.
What type of vulnerability is CVE-2026-2156?
CVE-2026-2156 is classified as a cross-site scripting (XSS) vulnerability.