在 SourceCodester Simple Student Information System 1.0 中发现了一个漏洞。该漏洞影响 Profile Field Handler 组件中对 /register.php 文件的某些未知处理逻辑。通过操纵参数 firstname/lastname,可导致跨站脚本攻击(XSS)。该攻击可由远程发起,相关利用代码已公开,存在被实际利用的风险。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Simple Student Information System | 1.0 |
cpe:2.3:a:sourcecodester:simple_student_information_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105807 | 7.3 HIGH | SourceCodester Simple Student Information System searchquery.php sql injection |
| CVE-2026-105704 | 7.3 HIGH | SourceCodester Drug Recommendation System Auth Guard improper authentication |
| CVE-2026-105706 | 4.3 MEDIUM | SourceCodester Drug Recommendation System cross-site request forgery |
| CVE-2026-105705 | 4.3 MEDIUM | SourceCodester Drug Recommendation System add_drug.php cross site scripting |
| CVE-2026-105808 | 3.5 LOW | SourceCodester Simple Student Information System searchresults.php clean cross site script |
No comments yet