CVE-2026-2222: code-projects Online Reviewer System btn_functions.php cross site scripting
A weakness has been identified in code-projects Online Reviewer System 1.0. Affected by this vulnerability is an unknown functionality of the file /system/system/admins/manage/users/btn_functions.php. Executing a manipulation of the argument firstname can lead to cross site scripting. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2222?
CVE-2026-2222 has been classified as a moderate severity vulnerability due to its potential for cross site scripting attacks.
How can I mitigate CVE-2026-2222?
To mitigate CVE-2026-2222, ensure proper input validation and output encoding for the affected btn_functions.php functionality.
What impacts could CVE-2026-2222 have on my system?
CVE-2026-2222 could allow an attacker to execute malicious scripts in users' browsers, leading to data theft or unauthorized actions.
Is there a patch available for CVE-2026-2222?
As of now, there is no official patch released for CVE-2026-2222, so applying security best practices is crucial.
Which versions of the Online Reviewer System are affected by CVE-2026-2222?
CVE-2026-2222 affects the Online Reviewer System version 1.0.