CVE-2026-14655
LOW
2.4
CVSS 3.1
Description
A weakness has been identified in code-projects Assessment Management 1.0. Affected by this issue is some unknown functionality of the file admin/view-users.php. Executing a manipulation of the argument User can lead to cross site scripting. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
Metadata
Severity & Metrics
2.4
LOW CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| code-projects | Assessment Management | — | 1.0 |
CVSS scores (4)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 4.8 | MEDIUM | 4.0 | cna | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P |
| 3.3 | N/D | 2.0 | cna | AV:N/AC:L/Au:M/C:N/I:P/A:N/E:POC/RL:ND/RC:UR |
| 2.4 | LOW | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R |
| 2.4 | LOW | 3.0 | cna | CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R |
References (6)
- VDB-376169 | code-projects Assessment Management view-users.php cross site scripting https://vuldb.com/vuln/376169
- VDB-376169 | CTI Indicators (IOB, IOC, TTP, IOA) https://vuldb.com/vuln/376169/cti
- CVE-2026-14655 | CVE Analysis and Report https://vuldb.com/cve/CVE-2026-14655
- Submit #846714 | Assessment Management System admin/view-users.php Stored XSS Vulnerability v1.0 Stored XSS https://vuldb.com/submit/846714
- https://github.com/zzzxc643/CVE1/blob/main/assessment/vul3.md
- https://code-projects.org/