CVE-2026-19904

medium

Description

A vulnerability was found in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the file /admin/index.php?page=site_settings of the component System Settings Module. The manipulation results in cross site scripting. The attack can be executed remotely. The exploit has been made public and could be used.

References

https://www.sourcecodester.com/

https://vuldb.com/vuln/390097/cti

https://vuldb.com/vuln/390097

https://vuldb.com/submit/870786

https://vuldb.com/cve/CVE-2026-19904

https://medium.com/@hemantrajbhati5555/stored-cross-site-scripting-xss-in-system-settings-module-fa4f99ed1544

Details

Source: Mitre, NVD

Published: 2026-08-15

Updated: 2026-08-15

Risk Information

CVSS v2

Base Score: 3.3

Vector: CVSS2#AV:N/AC:L/Au:M/C:N/I:P/A:N

Severity: Low

CVSS v3

Base Score: 2.4

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N

Severity: Low

CVSS v4

Base Score: 4.8

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Severity: Medium