Sceawere
Vulnerability Detail
CVE-2026-104612UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Student Result Management XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 10h ago
- Vendor
- SourceCodester
- Product
- Student Result Management System
- Attack Type
- Cross Site Scripting
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file script/academic/core/new_announcement.php of the component Announcement Module. The manipulation of the argument title/announcement results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be used.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-02T13:17:44.820Z",
"pubdate": "2026-10-02T13:17:44.820Z",
"executiveSummary": "A Cross-Site Scripting (XSS) vulnerability exists in the Announcement Module of SourceCodester Student Result Management System 1.0.\nThe vulnerability arises due to improper neutralization of user-supplied input within the title and announcement parameters.\nSuccessful exploitation allows remote attackers to inject malicious scripts into web pages viewed by other users, potentially leading to session hijacking, unauthorized actions, or the theft of sensitive session cookies.\nThe flaw affects the file script/academic/core/new_announcement.php, where unsanitized inputs are reflected back to the browser.\nThis vulnerability poses a significant risk to the integrity and confidentiality of the administrative and student interfaces.\nAttackers can leverage this flaw remotely, and since the exploit is publicly available, the system is exposed to immediate risks from unauthenticated or authenticated threat actors depending on the specific application access control implementation.",
"technicalDetails": "The vulnerability is identified as a Stored Cross-Site Scripting (XSS) flaw located within the Announcement Module of the SourceCodester Student Result Management System 1.0.\nThe root cause of this security defect is the failure of the server-side application to perform adequate input validation and output encoding on the title and announcement parameters processed by the script/academic/core/new_announcement.php file.\nWhen a user or administrator submits data through the announcement creation interface, the application accepts the input without stripping or escaping HTML tags and JavaScript event handlers.\nAn attacker can exploit this by crafting a malicious payload—such as <script>alert(document.cookie)</script>—and submitting it as the title or content of an announcement.\nOnce the input is saved to the backend database, it is rendered on the frontend whenever a student or another administrator views the announcements.\nThe browser interprets the injected script as legitimate code originating from the trusted origin of the Student Result Management System, executing the script within the context of the victim's session.\nThe attack flow follows these steps: 1) The attacker accesses the Announcement Module via the vulnerable script; 2) The attacker injects a malicious JavaScript payload into the title or announcement fields; 3) The server stores the malicious input into the database without sanitization; 4) The victim triggers the execution of the payload by navigating to the page where the announcement is displayed; 5) The browser executes the script, allowing the attacker to perform actions on behalf of the victim or exfiltrate sensitive data.\nBecause the exploit is remotely accessible, the threat is elevated, enabling attackers to perform unauthorized administrative actions, redirect users to malicious domains, or intercept sensitive authentication tokens. The lack of proper output encoding at the point of reflection in the affected file allows for the persistent execution of arbitrary code across different user sessions."
}