CVE-2026-93976: code-projects Assessment Management add-user.php cross site scripting
Published Sep 20, 2026
·Updated
A vulnerability was found in code-projects Assessment Management 1.0. Affected is an unknown function of the file admin/add-user.php. The manipulation of the argument level results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could be used.
Affected Software
1 affected component
Code-projects Assessment Management=1.0
Event History
Sep 20, 2026
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access and interaction are needed to exploit this issue?
The CVSS vector indicates an attacker needs high privileges and a user must interact with the malicious content. The attack can be launched remotely and has low attack complexity.
2
Which input should be investigated for exposure?
The affected behavior is in admin/add-user.php and involves the level argument. Review whether this parameter is properly validated and output-encoded wherever it is displayed.
3
Is public exploit information available?
Yes. The available data states that an exploit has been made public and could be used.