CVE 4.8 MEDIUM

code-projects Chat System send_message.php cross site scripting_CVE-2026-7090

4.8 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P

Description

A vulnerability was detected in code-projects Chat System 1.0. This affects an unknown function of the file /admin/send_message.php of the component Chat Interface. The manipulation of the argument msg results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used.

Basic Information

ID CVE-2026-7090
Source VulDB
Published Apr 27, 2026 at 05:15

Affected Product

Vendor code-projects
Product Chat System
Version 1.0
Affected Versions code-projects Chat System 1.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.