CVE-2026-4356 describes a cross-site scripting (XSS) vulnerability in itsourcecode University Management System 1.0, specifically within the /add_result.php file when manipulating the 'vr' argument. This low-severity flaw (CVSS 2.4) can be exploited remotely by an attacker with high privileges, requiring user interaction, and primarily poses a low integrity risk. While an exploit has been published, there is no evidence of active exploitation (KEV: No), and it currently shows minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Itsourcecode | University Management System | 1.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.