CVE-2026-4474: itsourcecode University Management System admin_single_student_update.php cross site scripting
A flaw has been found in itsourcecode University Management System 1.0. Impacted is an unknown function of the file /adminsinglestudentupdate.php. This manipulation of the argument stname causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4474?
CVE-2026-4474 has been classified with a moderate severity level due to its potential impact on user data exposure through cross-site scripting.
How do I fix CVE-2026-4474?
To fix CVE-2026-4474, ensure input validation and output encoding are implemented in the /admin_single_student_update.php file.
What systems are affected by CVE-2026-4474?
CVE-2026-4474 affects the itsourcecode University Management System version 1.0.
Can CVE-2026-4474 lead to a data breach?
Yes, CVE-2026-4474 can allow attackers to execute scripts in the user's browser, potentially leading to a data breach.
Is there a patch available for CVE-2026-4474?
As of now, no specific patch has been released for CVE-2026-4474, so manual remediation is necessary.