CVE-2026-14656
MEDIUM
4.3
CVSS 3.1
Description
A security vulnerability has been detected in code-projects Assessment Management 1.0. This affects an unknown part of the file /admin/remove-user.php. The manipulation of the argument ID leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
Metadata
Severity & Metrics
4.3
MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| code-projects | Assessment Management | — | 1.0 |
CVSS scores (4)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 5.3 | MEDIUM | 4.0 | cna | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P |
| 5.0 | N/D | 2.0 | cna | AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR |
| 4.3 | MEDIUM | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R |
| 4.3 | MEDIUM | 3.0 | cna | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R |
References (6)
- VDB-376170 | code-projects Assessment Management remove-user.php cross site scripting https://vuldb.com/vuln/376170
- VDB-376170 | CTI Indicators (IOB, IOC, TTP, IOA) https://vuldb.com/vuln/376170/cti
- CVE-2026-14656 | CVE Analysis and Report https://vuldb.com/cve/CVE-2026-14656
- Submit #846715 | Assessment Management System admin/remove-user.php Reflected XSS Vulnerability v1.0 Reflected XSS https://vuldb.com/submit/846715
- https://github.com/zzzxc643/CVE1/blob/main/assessment/vul4.md
- https://code-projects.org/