CVE-2026-4969
⚪ Do wiadomości
Wstrzyknięcie skryptów w Social Networking Site umożliwia atak XSS zdalnie.
CVSS
3.5
EPSS
0.0%
Exploit
none
Vendor
Opis źródłowy (NVD)
A vulnerability was identified in code-projects Social Networking Site 1.0. The impacted element is an unknown function of the file /home.php of the component Alert Handler. The manipulation of the argument content leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
xss
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 3.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.0% |
| Opublikowano (NVD) | 2026-03-27 19:16:44 UTC |
| Ostatnia modyfikacja (NVD) | 2026-04-24 16:36:24 UTC |
Referencje
- https://code-projects.org/ (cna@vuldb.com)
- https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Stored%20Cross-Site%20Scripting%20(XSS)%20in%20PHP%20Social%20Networking%20Site.md (cna@vuldb.com)
- https://vuldb.com/?ctiid.353856 (cna@vuldb.com)
- https://vuldb.com/?id.353856 (cna@vuldb.com)
- https://vuldb.com/?submit.777815 (cna@vuldb.com)