CVE-2026-95957: SourceCodester Smart Attendance System with QR Code Scanner Self-Registration student_signup.php prepend cross site scripting

Published Sep 23, 2026
·
Updated

A vulnerability was found in SourceCodester Smart Attendance System with QR Code Scanner 1.0. This issue affects the function prepend of the file studentsignup.php of the component Self-Registration. Performing a manipulation of the argument fullname results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

Affected Software

1 affected component
Sourcecodester Smart Attendance System with QR Code Scanner=1.0

Event History

Sep 23, 2026
CVE Published
via MITRE·02:30 AM
Data Sourced
via MITRE·02:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What does an attacker need to exploit this issue?

An attacker can exploit it remotely by submitting a crafted full_name value through the self-registration functionality. No privileges are required, but exploitation requires user interaction.

2

Are systems running the affected release exposed by default?

The issue is in the Self-Registration component's student_signup.php endpoint. Deployments where users can access and use self-registration are exposed to the affected full_name input handling.

3

How urgent is remediation?

Public exploit information is available, which increases the likelihood of attempted exploitation. Prioritize remediation or restrict access to the self-registration function while a fix is unavailable.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203