CVE-2026-93975: code-projects Assessment Management User Editing edit-user.php cross site scripting
Published Sep 20, 2026
·Updated
A vulnerability has been found in code-projects Assessment Management 1.0. This impacts an unknown function of the file admin/edit-user.php of the component User Editing. The manipulation of the argument name/sname/email/username/password/id leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
Code-projects Assessment Management=1.0
Event History
Sep 20, 2026
CVE Published
via MITRE·09:45 AM
Data Sourced
via MITRE·09:45 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs high privileges and user interaction, according to the supplied CVSS vector. The attack can be initiated remotely, and a public exploit has been disclosed.
2
Which inputs should be treated as affected?
The affected User Editing functionality in admin/edit-user.php accepts the name, sname, email, username, password, and id arguments. Manipulation of these arguments can lead to cross-site scripting.