CVE-2026-86278

A vulnerability was found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The affected element is an unknown function of the file manage_subjects.php. The manipulation of the argument msg/title/content results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-07 07:16

Updated : 2026-09-08 15:18


NVD link : CVE-2026-86278

Mitre link : CVE-2026-86278

CVE.ORG link : CVE-2026-86278


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')