CVE-2026-5106

A flaw has been found in code-projects Exam Form Submission 1.0. The impacted element is an unknown function of the file /admin/update_fst.php. Executing a manipulation of the argument sname can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used.
References
Link Resource
https://code-projects.org/ Product
https://github.com/sxc2044-pixel/hajimi/issues/1 Permissions Required VDB Entry
https://vuldb.com/submit/780091 Third Party Advisory VDB Entry
https://vuldb.com/vuln/354131 Third Party Advisory VDB Entry
https://vuldb.com/vuln/354131/cti Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:code-projects:exam_form_submission:1.0:*:*:*:*:*:*:*

History

30 Mar 2026, 15:39

Type Values Removed Values Added
CPE cpe:2.3:a:code-projects:exam_form_submission:1.0:*:*:*:*:*:*:*
First Time Code-projects exam Form Submission
Code-projects
References () https://code-projects.org/ - () https://code-projects.org/ - Product
References () https://github.com/sxc2044-pixel/hajimi/issues/1 - () https://github.com/sxc2044-pixel/hajimi/issues/1 - Permissions Required, VDB Entry
References () https://vuldb.com/submit/780091 - () https://vuldb.com/submit/780091 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/354131 - () https://vuldb.com/vuln/354131 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/354131/cti - () https://vuldb.com/vuln/354131/cti - Third Party Advisory, VDB Entry

Information

Published : 2026-03-30 05:15

Updated : 2026-03-30 15:39


NVD link : CVE-2026-5106

Mitre link : CVE-2026-5106

CVE.ORG link : CVE-2026-5106


JSON object : View

Products Affected

code-projects

  • exam_form_submission
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')