CVE-2026-4576: code-projects Exam Form Submission update_s5.php cross site scripting
A vulnerability has been found in code-projects Exam Form Submission 1.0. Impacted is an unknown function of the file /admin/updates5.php. Such manipulation of the argument sname leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4576?
CVE-2026-4576 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2026-4576?
To fix CVE-2026-4576, ensure proper input validation and escaping of user-generated content in the /admin/update_s5.php file.
Who is affected by CVE-2026-4576?
CVE-2026-4576 affects users of Code-Projects Exam Form Submission version 1.0.
What type of vulnerability is CVE-2026-4576?
CVE-2026-4576 is a cross-site scripting (XSS) vulnerability.
What component of the software is vulnerable in CVE-2026-4576?
The vulnerability in CVE-2026-4576 resides in the /admin/update_s5.php file.