Sceawere

Vulnerability Detail

CVE-2026-104612UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Student Result Management XSS

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
10h ago
Vendor
SourceCodester
Product
Student Result Management System
Attack Type
Cross Site Scripting
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file script/academic/core/new_announcement.php of the component Announcement Module. The manipulation of the argument title/announcement results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be used.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-02T13:17:44.820Z",
  "pubdate": "2026-10-02T13:17:44.820Z",
  "executiveSummary": "A Cross-Site Scripting (XSS) vulnerability exists in the Announcement Module of SourceCodester Student Result Management System 1.0.\nThe vulnerability arises due to improper neutralization of user-supplied input within the title and announcement parameters.\nSuccessful exploitation allows remote attackers to inject malicious scripts into web pages viewed by other users, potentially leading to session hijacking, unauthorized actions, or the theft of sensitive session cookies.\nThe flaw affects the file script/academic/core/new_announcement.php, where unsanitized inputs are reflected back to the browser.\nThis vulnerability poses a significant risk to the integrity and confidentiality of the administrative and student interfaces.\nAttackers can leverage this flaw remotely, and since the exploit is publicly available, the system is exposed to immediate risks from unauthenticated or authenticated threat actors depending on the specific application access control implementation.",
  "technicalDetails": "The vulnerability is identified as a Stored Cross-Site Scripting (XSS) flaw located within the Announcement Module of the SourceCodester Student Result Management System 1.0.\nThe root cause of this security defect is the failure of the server-side application to perform adequate input validation and output encoding on the title and announcement parameters processed by the script/academic/core/new_announcement.php file.\nWhen a user or administrator submits data through the announcement creation interface, the application accepts the input without stripping or escaping HTML tags and JavaScript event handlers.\nAn attacker can exploit this by crafting a malicious payload—such as <script>alert(document.cookie)</script>—and submitting it as the title or content of an announcement.\nOnce the input is saved to the backend database, it is rendered on the frontend whenever a student or another administrator views the announcements.\nThe browser interprets the injected script as legitimate code originating from the trusted origin of the Student Result Management System, executing the script within the context of the victim's session.\nThe attack flow follows these steps: 1) The attacker accesses the Announcement Module via the vulnerable script; 2) The attacker injects a malicious JavaScript payload into the title or announcement fields; 3) The server stores the malicious input into the database without sanitization; 4) The victim triggers the execution of the payload by navigating to the page where the announcement is displayed; 5) The browser executes the script, allowing the attacker to perform actions on behalf of the victim or exfiltrate sensitive data.\nBecause the exploit is remotely accessible, the threat is elevated, enabling attackers to perform unauthorized administrative actions, redirect users to malicious domains, or intercept sensitive authentication tokens. The lack of proper output encoding at the point of reflection in the affected file allows for the persistent execution of arbitrary code across different user sessions."
}
CVE-2026-104612: Student Result Management XSS (MEDIUM Severity, CVSS: 4.3) | Sceawere