CVE-2026-86294: SourceCodester Simple Traffic Offense System Settings Update Endpoint save-settings.php cross site scripting
A vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this issue is some unknown functionality of the file save-settings.php of the component Settings Update Endpoint. The manipulation of the argument sitename/sitedesc leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
Does exploitation require an authenticated account or local access?
No authenticated privileges are required, and the issue can be exploited remotely. Successful exploitation requires user interaction.
Which deployment version is identified as affected?
The reported affected version is SourceCodester Simple Traffic Offense System 1.0. The available information does not identify other affected or fixed versions.
Is exploit code or exploit information publicly available?
Yes. The exploit has been publicly disclosed and may be used.