CVE-2026-4972: code-projects Online Reviewer System btn_functions.php cross site scripting
A security vulnerability has been detected in code-projects Online Reviewer System up to 1.0. Affected is an unknown function of the file /system/system/students/assessments/databank/btnfunctions.php. Such manipulation of the argument Description leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4972?
CVE-2026-4972 has been identified as a cross-site scripting vulnerability in the Code-Projects Online Reviewer System.
How do I fix CVE-2026-4972?
To fix CVE-2026-4972, you should update the Code-Projects Online Reviewer System to a version higher than 1.0.
What is the affected software for CVE-2026-4972?
CVE-2026-4972 affects Code-Projects Online Reviewer System versions up to and including 1.0.
Where is CVE-2026-4972 located in the software?
CVE-2026-4972 is found in the btn_functions.php file located at /system/system/students/assessments/databank/.
What type of vulnerability is CVE-2026-4972?
CVE-2026-4972 is categorized as a cross-site scripting (XSS) vulnerability.