CVE-2026-105809: fallo de gravedad media en SourceCodester Simple Student Information System
SourceCodester Simple Student Information System Profile Field register.php cross site scripting
Publicada el
33Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 5.3epss 0.3%
probabilidad de explotación
0.3%top 74% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
A vulnerability was identified in SourceCodester Simple Student Information System 1.0. This issue affects some unknown processing of the file /register.php of the component Profile Field Handler. The manipulation of the argument firstname/lastname leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly available and might be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
Productos afectados
SourceCodester · Simple Student Information SystemPoCs públicas encontradas — 1
cve_referencegithub.com/wsx138/cve/issues/7no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
CVEs relacionadas — SourceCodester Simple Student Information System
En el mismo producto, de las más peligrosas a las menos.
CVE-2022-2722MEDIUMSourceCodester Simple Student Information System manage_course.php sql injectionEPSS 0.9%CVE-2022-2705MEDIUMSourceCodester Simple Student Information System manage_department.php sql injectionEPSS 0.8%CVE-2023-2425LOWSourceCodester Simple Student Information System Add New Course cross site scriptingEPSS 0.6%CVE-2026-19710MEDIUMSourceCodester Simple Student Information System view_department.php sql injectionEPSS 0.4%CVE-2026-105808MEDIUMSourceCodester Simple Student Information System searchresults.php clean cross site scriptingEPSS 0.3%CVE-2026-105807MEDIUMSourceCodester Simple Student Information System searchquery.php sql injectionEPSS 0.3%