UNKNOWNCVE-2026-5106

code-projects Exam Form Submission update_fst.php cross site scripting

Platform

php

Component

hajimi

A flaw has been found in code-projects Exam Form Submission 1.0. The impacted element is an unknown function of the file /admin/update_fst.php. Executing a manipulation of the argument sname can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used.

How to fix

Actualizar a una versión parcheada o aplicar las medidas de seguridad necesarias para evitar la inyección de código malicioso a través del parámetro 'sname' en el archivo '/admin/update_fst.php'. Validar y limpiar las entradas del usuario para prevenir ataques de Cross-Site Scripting (XSS).

Monitor your dependencies automatically

Get notified when new vulnerabilities affect your projects. Free forever.

Start free