CVE-2026-86294CWE-79CWE-94

SourceCodester Simple Traffic Offense System Settings Update Endpoint save-settings.php cross site scripting

Medium · published September 7, 2026

CVSS v3.1
4.3
EPSS
In the wild
Unconfirmed
What it is

A vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this issue is some unknown functionality of the file save-settings.php of the component Settings Update Endpoint. The manipulation of the argument site_name/site_desc leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

The record
Technical detail
CVSS v3.1
4.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R
CVSS v4.0
5.3 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
EPSS
Not scored
Weaknesses
CWE-79 · Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'); CWE-94 · Improper Control of Generation of Code ('Code Injection')
Published
2026-09-07T10:00Z
Timeline
  • 07 SEP 10:00Z
    SourceCodester Simple Traffic Offense System Settings Update Endpoint save-settings.php cross site scripting
    cvelistv5