CVE Database
/

CVE-2026-9518

Back to search

CVE-2026-9518

Published: May 26, 2026

Modified: May 29, 2026

PUBLISHED

CVSS v3.1

4.3

MEDIUM

Description

A vulnerability was identified in hemant6488 CodeIgniter-StudentManagementSystem. The impacted element is the function addStudent of the file view_students.php of the component Students Controller. The manipulation of the argument Name leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.

VendorProductVersions

hemant6488

CodeIgniter-StudentManagementSystem

affected
9abd69448c66555d434755e6bd0b099a8527a0a9
affected
9157e0c28b177fdbe69cf76e878eca365fedbf5f
affected
f2e07d2ecd007fa1429f0444510ad95a8d0d7c73

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Unchanged

Confidentiality

None

Integrity

Low

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now