5.1
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was detected in code-projects Online Reviewer System 1.0. This affects an unknown part of the file /system/system/admins/manage/users/btn_functions.php. The manipulation of the argument firstname results in cross site scripting. It is possible to launch the attack remotely. The exploit is now public and may be used.
Basic Information
ID
CVE-2026-2224
Source
VulDB
Published
Feb 9, 2026 at 08:32
Affected Product
Vendor
code-projects
Product
Online Reviewer System
Version
1.0
Affected Versions
code-projects Online Reviewer System 1.0