CVE-2026-7110: code-projects Invoice System in Laravel item cross site scripting
A flaw has been found in code-projects Invoice System in Laravel 1.0. Affected is an unknown function of the file /item. Executing a manipulation of the argument item name/description can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7110?
CVE-2026-7110 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2026-7110?
To fix CVE-2026-7110, sanitize and validate user inputs in the item name and description fields to prevent XSS vulnerabilities.
What software is affected by CVE-2026-7110?
CVE-2026-7110 affects version 1.0 of the Code-Projects Invoice System in Laravel.
What type of vulnerability is CVE-2026-7110?
CVE-2026-7110 is a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
Can I exploit CVE-2026-7110 without authentication?
Yes, CVE-2026-7110 can potentially be exploited without authentication, targeting the item name and description fields directly.