{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-9485", "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "state": "PUBLISHED", "assignerShortName": "VulDB", "dateReserved": "2026-05-24T09:26:27.614Z", "datePublished": "2026-05-25T19:15:09.731Z", "dateUpdated": "2026-05-26T12:38:45.429Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "shortName": "VulDB", "dateUpdated": "2026-05-25T19:15:09.731Z" }, "title": "SourceCodester Student Grades Management System students.php cross site scripting", "problemTypes": [ { "descriptions": [ { "type": "CWE", "cweId": "CWE-79", "lang": "en", "description": "Cross Site Scripting" } ] }, { "descriptions": [ { "type": "CWE", "cweId": "CWE-94", "lang": "en", "description": "Code Injection" } ] } ], "affected": [ { "vendor": "SourceCodester", "product": "Student Grades Management System", "versions": [ { "version": "1.0", "status": "affected" } ], "cpes": [ "cpe:2.3:a:sourcecodester:student_grades_management_system:*:*:*:*:*:*:*:*" ] } ], "descriptions": [ { "lang": "en", "value": "A vulnerability was identified in SourceCodester Student Grades Management System 1.0. Affected by this issue is some unknown functionality of the file students.php. The manipulation of the argument Remarks leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used." } ], "metrics": [ { "cvssV4_0": { "version": "4.0", "baseScore": 5.1, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P", "baseSeverity": "MEDIUM" } }, { "cvssV3_1": { "version": "3.1", "baseScore": 3.5, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R", "baseSeverity": "LOW" } }, { "cvssV3_0": { "version": "3.0", "baseScore": 3.5, "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R", "baseSeverity": "LOW" } }, { "cvssV2_0": { "version": "2.0", "baseScore": 4, "vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR" } } ], "timeline": [ { "time": "2026-05-24T00:00:00.000Z", "lang": "en", "value": "Advisory disclosed" }, { "time": "2026-05-24T02:00:00.000Z", "lang": "en", "value": "VulDB entry created" }, { "time": "2026-05-24T11:31:57.000Z", "lang": "en", "value": "VulDB entry last update" } ], "credits": [ { "lang": "en", "value": "GeekerA (VulDB User)", "type": "reporter" } ], "references": [ { "url": "https://vuldb.com/vuln/365466", "name": "VDB-365466 | SourceCodester Student Grades Management System students.php cross site scripting", "tags": [ "vdb-entry", "technical-description" ] }, { "url": "https://vuldb.com/vuln/365466/cti", "name": "VDB-365466 | CTI Indicators (IOB, IOC, TTP, IOA)", "tags": [ "signature", "permissions-required" ] }, { "url": "https://vuldb.com/submit/814043", "name": "Submit #814043 | SourceCodester Student Grades Management System 1.0 Cross Site Scripting", "tags": [ "third-party-advisory" ] }, { "url": "https://github.com/Jack-MRJ/Student-Grades-Management-System-Vulnerability-Report", "tags": [ "exploit" ] }, { "url": "https://www.sourcecodester.com/", "tags": [ "product" ] } ], "tags": [ "x_freeware" ] }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-05-26T12:38:33.073778Z", "id": "CVE-2026-9485", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-05-26T12:38:45.429Z" } } ] } }