Sceawere
Vulnerability Detail
CVE-2026-105809UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Reflected XSS in Simple Student Information System
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 16h ago
- Vendor
- SourceCodester
- Product
- Simple Student Information System
- Attack Type
- Cross Site Scripting
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was identified in SourceCodester Simple Student Information System 1.0. This issue affects some unknown processing of the file /register.php of the component Profile Field Handler. The manipulation of the argument firstname/lastname leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly available and might be used.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-06T09:17:41.410Z",
"pubdate": "2026-10-06T09:17:41.410Z",
"executiveSummary": "A Cross-Site Scripting (XSS) vulnerability exists within the Simple Student Information System 1.0. The vulnerability is located in the Profile Field Handler component, specifically within the /register.php file.\nThe flaw allows remote attackers to inject malicious scripts into the application by manipulating the 'firstname' or 'lastname' input arguments. When a victim interacts with the rendered output, the injected payload executes within the context of the user's browser session.\nSuccessful exploitation can result in unauthorized session hijacking, theft of sensitive authentication cookies, or redirection to malicious domains. This vulnerability carries significant risk as it allows for the subversion of client-side security controls and potential full account takeover. The attack can be initiated remotely without specific user interaction beyond accessing the affected profile page. As an exploit is publicly available, the risk of exploitation is elevated for systems that remain unpatched or unhardened.",
"technicalDetails": "The vulnerability is a classic Reflected Cross-Site Scripting (XSS) flaw occurring within the Profile Field Handler of the SourceCodester Simple Student Information System 1.0. The root cause is the failure of the application to properly sanitize or validate user-supplied input provided to the 'firstname' and 'lastname' parameters in the /register.php endpoint prior to reflecting that input in the HTML response body.\nWhen a user submits data to /register.php, the backend application processes these arguments and includes them directly in the generated HTML document without implementing context-aware output encoding. Because the application fails to neutralize characters such as <, >, \", and ', an attacker can inject arbitrary JavaScript or HTML payloads into the fields.\nThe attack flow proceeds as follows: An attacker crafts a malicious URL containing a JavaScript payload within the 'firstname' or 'lastname' arguments. This URL is then sent to a target user. When the target user follows the link, the server-side logic processes the input and reflects the payload back to the browser. The victim's browser, interpreting the reflected input as legitimate source code, executes the injected script within the security context of the Simple Student Information System domain.\nThis execution allows the attacker to access document.cookie to steal session identifiers, perform actions on behalf of the authenticated user, or exfiltrate sensitive data displayed on the page. Since the script runs with the permissions of the victim's session, any action the user can perform within the system is potentially actionable by the attacker. There are no specialized privilege requirements for this exploit, as the input processing happens at the registration and profile handling stage, which is often accessible to unauthenticated or low-privileged users depending on specific system configurations. The vulnerability is reachable over the network and can be exploited remotely by anyone with access to the /register.php file."
}