CVE-2026-4595: code-projects Exam Form Submission update_s6.php cross site scripting
A vulnerability was determined in code-projects Exam Form Submission 1.0. This vulnerability affects unknown code of the file /admin/updates6.php. Executing a manipulation of the argument sname can lead to cross site scripting. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4595?
CVE-2026-4595 has a medium severity level due to the potential for cross-site scripting attacks.
How do I fix CVE-2026-4595?
To fix CVE-2026-4595, sanitize and validate user inputs in the sname parameter of the update_s6.php file.
What software versions are affected by CVE-2026-4595?
CVE-2026-4595 affects version 1.0 of Code-projects Exam Form Submission.
Can CVE-2026-4595 lead to data breaches?
Yes, CVE-2026-4595 can potentially lead to data breaches through exploitation of the cross-site scripting vulnerability.
Who is the vendor for CVE-2026-4595?
The vendor for CVE-2026-4595 is code-projects.