CVE-2026-7090: code-projects Chat System send_message.php cross site scripting
A vulnerability was detected in code-projects Chat System 1.0. This affects an unknown function of the file /admin/sendmessage.php of the component Chat Interface. The manipulation of the argument msg results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7090?
CVE-2026-7090 is classified as a high-severity cross site scripting vulnerability.
How do I fix CVE-2026-7090?
To fix CVE-2026-7090, sanitize and validate the 'msg' input in the /admin/send_message.php file to prevent XSS.
What systems are affected by CVE-2026-7090?
CVE-2026-7090 affects Code-Projects Chat System version 1.0.
Can CVE-2026-7090 lead to data theft?
Yes, CVE-2026-7090 can allow an attacker to execute malicious scripts, potentially leading to data theft.
What are the impacts of CVE-2026-7090?
The impact of CVE-2026-7090 includes unauthorized access to user sessions and data through cross site scripting.