Sceawere

Vulnerability Detail

CVE-2026-105808UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Reflected XSS in Simple Student Information System

Vulnerability Metadata

Severity
Low
Score / CVSS
3.5
Creation Date
16h ago
Vendor
SourceCodester
Product
Simple Student Information System
Attack Type
Cross Site Scripting
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was determined in SourceCodester Simple Student Information System 1.0. This vulnerability affects the function clean of the file searchresults.php. Executing a manipulation of the argument searchbox can lead to cross site scripting. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.5",
  "pubDate": "2026-10-06T09:17:41.193Z",
  "pubdate": "2026-10-06T09:17:41.193Z",
  "executiveSummary": "A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in SourceCodester Simple Student Information System version 1.0.\nThe vulnerability resides within the search functionality of the application, specifically targeting the searchbox argument in the file searchresults.php.\nBy injecting malicious scripts into the searchbox parameter, an unauthenticated remote attacker can force the victim's browser to execute arbitrary JavaScript code within the context of the user's session.\nThis vulnerability poses a significant security risk, as it allows attackers to bypass same-origin policy protections to conduct session hijacking, cookie theft, or unauthorized actions on behalf of the authenticated user.\nThe flaw is publicly disclosed and exploitable remotely, requiring no prior authentication or system privileges to execute the attack. Users of this version are at immediate risk of script injection attacks if they interact with crafted links provided by an attacker.",
  "technicalDetails": "The vulnerability is a classic case of Reflected Cross-Site Scripting (XSS) caused by improper neutralization of user-supplied input within the searchresults.php script. The application fails to adequately sanitize the input received via the searchbox parameter before echoing it back to the user's browser in the HTTP response.\nThe root cause lies in the clean function, which is designed to handle input processing but fails to implement robust output encoding or filtering mechanisms to prevent the interpretation of HTML/JavaScript tags. When an attacker crafts a malicious URL containing a JavaScript payload within the searchbox argument and tricks a user into clicking it, the application reflects the payload directly into the rendered HTML page.\nThe attack flow proceeds as follows: First, the attacker identifies that the searchbox parameter in searchresults.php directly reflects input into the document object model (DOM). Second, the attacker constructs a URL containing an encoded script payload (e.g., <script>alert('XSS')</script>) assigned to the searchbox argument. Third, the attacker delivers this URL to a target user via social engineering or other vectors. When the target user navigates to the malicious link, the server processes the request and sends a response containing the unescaped script tag. Finally, the user's browser parses the response and executes the injected script within the security context of the Simple Student Information System domain.\nBecause the execution occurs in the victim's browser, the attacker can gain access to sensitive information such as session cookies, CSRF tokens, and authentication headers, facilitating session hijacking. Furthermore, the attacker could manipulate the Document Object Model to present fraudulent login forms (phishing) or perform unauthorized API requests under the identity of the victim. The vulnerability is network-exposed and does not require the attacker to have an existing account on the system, making it an attractive target for remote exploitation."
}
CVE-2026-105808: Reflected XSS in Simple Student Information System (LOW Severity, CVSS: 3.5) | Sceawere