CVE-2026-4578: code-projects Exam Form Submission update_s3.php cross site scripting
A vulnerability was determined in code-projects Exam Form Submission 1.0. The impacted element is an unknown function of the file /admin/updates3.php. Executing a manipulation of the argument sname can lead to cross site scripting. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4578?
CVE-2026-4578 is classified as a moderate severity cross site scripting vulnerability.
How do I fix CVE-2026-4578?
To fix CVE-2026-4578, sanitize and validate the input from the 'sname' argument in the update_s3.php file.
What software is affected by CVE-2026-4578?
CVE-2026-4578 affects Code-projects Exam Form Submission version 1.0.
What type of attack can CVE-2026-4578 facilitate?
CVE-2026-4578 can facilitate cross site scripting (XSS) attacks by manipulating the 'sname' argument.
Where is the vulnerability located in the software for CVE-2026-4578?
CVE-2026-4578 is located in the /admin/update_s3.php file of the Code-projects Exam Form Submission application.