Description
A vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this issue is some unknown functionality of the file save-settings.php of the component Settings Update Endpoint. The manipulation of the argument site_name/site_desc leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Published: 2026-09-07
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross-site scripting (client‑side injection)
Action: Apply Patch
AI Analysis

Impact

The flaw is in the Settings Update Endpoint’s save-settings.php where the arguments site_name and site_desc are not properly validated or sanitized before being reflected in the web page. An attacker can inject malicious scripts that execute in the victim’s browser, which can lead to session hijacking, defacement, or further client‑side compromise. The vulnerability is classified as Type 79 (XSS) and also involves potential code injection (Type 94).

Affected Systems

The affected product is SourceCodester Simple Traffic Offense System version 1.0. No other vendors or product versions are listed. The attack surface is limited to the save‑settings.php upload interface, but once injected, the payload runs in the context of any user who views the affected page.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate impact. The EPSS score is not available, but the vulnerability is publicly disclosed and remote exploitation is possible, meaning an attacker can plant a script by送ting a crafted POST request to the endpoint without any special local privileges. The flaw is not yet cataloged in CISA KEV, so no known active exploitation campaigns have been reported. Nonetheless, due to the widespread use of XSS for credential theft and phishing, the risk to users that rely on the affected system is significant and should be mitigated promptly.

Generated by OpenCVE AI on September 7, 2026 at 13:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest version of the SourceCodester Simple Traffic Offense System if a vendor patch is available
  • Sanitize and escape all user input for site_name and site_desc on both server and client side to neutralize script tags
  • Deploy a web application firewall or content security policy that blocks inline scripts and restricts the allowed script origins

Generated by OpenCVE AI on September 7, 2026 at 13:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this issue is some unknown functionality of the file save-settings.php of the component Settings Update Endpoint. The manipulation of the argument site_name/site_desc leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Title SourceCodester Simple Traffic Offense System Settings Update Endpoint save-settings.php cross site scripting
First Time appeared Sourcecodester
Sourcecodester simple Traffic Offense System
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:sourcecodester:simple_traffic_offense_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester simple Traffic Offense System
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Simple Traffic Offense System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-11T20:35:15.595Z

Reserved: 2026-09-06T15:55:02.600Z

Link: CVE-2026-86294

cve-icon Vulnrichment

Updated: 2026-09-11T20:02:56.580Z

cve-icon NVD

Status : Deferred

Published: 2026-09-07T11:17:39.180

Modified: 2026-09-11T21:17:43.930

Link: CVE-2026-86294

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T13:45:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')