CVE-2026-9377: SourceCodester SUP Online Shopping productedit.php cross site scripting
A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of the file /admin/productedit.php. The manipulation of the argument productName leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9377?
The severity of CVE-2026-9377 is rated as low with a score of 2.4.
How do I fix CVE-2026-9377?
To fix CVE-2026-9377, ensure proper validation and sanitization of the 'productName' input in the productedit.php file.
What type of vulnerability is CVE-2026-9377?
CVE-2026-9377 is a cross-site scripting (XSS) vulnerability.
Can CVE-2026-9377 be exploited remotely?
Yes, CVE-2026-9377 can be exploited remotely due to the nature of the vulnerability.
What is the affected component in CVE-2026-9377?
The affected component in CVE-2026-9377 is the 'productedit.php' file in SourceCodester SUP Online Shopping.