CVE-2026-4576 describes a Cross-Site Scripting (XSS) vulnerability in code-projects Exam Form Submission 1.0, specifically affecting the /admin/update_s5.php file through manipulation of the 'sname' argument. This vulnerability carries a low CVSS score of 2.4, requiring high privileges and user interaction for a remote attack, with a low impact on integrity. Although the exploit has been publicly disclosed, there is no evidence of active exploitation, nor are there readily available exploit modules in common databases like Metasploit or ExploitDB. Community discussion and media coverage are currently non-existent, and its EPSS score is extremely low, indicating a minimal immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Code-Projects | Exam Form Submission | 1.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.