Description
A vulnerability was identified in code-projects Record Management System 1.0. Affected is an unknown function of the file main/reg.php. Such manipulation of the argument desc leads to cross site scripting. The attack may be launched remotely. The exploit is publicly available and might be used.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting via the desc parameter in Reg.php
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in Reg.php of the Record Management System and allows an attacker to inject arbitrary JavaScript through manipulation of the desc parameter. This stored cross‑site scripting flaw (CWE‑79) enables the execution of malicious script in the context of any user who views the stored data. Additionally, the flaw may involve code injection (CWE‑94), potentially expanding the impact beyond script execution.

Affected Systems

The affected product is code‑projects Record Management System version 1.0. It is relevant to installations that use the main/reg.php registration function and accept a desc argument. Any user interacting with this registration path is potentially exposed.

Risk and Exploitability

The CVSS score of 5.3 places the issue in the moderate risk range, and the vulnerability is not listed in the KEV catalog, with an EPSS score of less than 1%. The flaw can be triggered remotely by supplying a malicious desc value via a URL or form submission. Because it is stored, the injected payload remains in the system and will run for all subsequent users who view the impacted data. The public availability of an exploit indicates that an attacker could use existing tools without additional development.

Generated by OpenCVE AI on September 20, 2026 at 15:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Record Management System to the latest version that contains the vendor’s patch for the Reg.php XSS flaw.
  • Validate and escape all user‑supplied data in the desc field before storing or displaying it, such as by preserving only safe characters or stripping script tags.
  • Implement a Content‑Security‑Policy header or use a Web Application Firewall to detect or block script injection attempts.

Generated by OpenCVE AI on September 20, 2026 at 15:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in code-projects Record Management System 1.0. Affected is an unknown function of the file main/reg.php. Such manipulation of the argument desc leads to cross site scripting. The attack may be launched remotely. The exploit is publicly available and might be used.
Title code-projects Record Management System reg.php cross site scripting
First Time appeared Code-projects
Code-projects record Management System
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:code-projects:record_management_system:*:*:*:*:*:*:*:*
Vendors & Products Code-projects
Code-projects record Management System
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Code-projects Record Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-22T15:46:21.634Z

Reserved: 2026-09-15T09:04:59.408Z

Link: CVE-2026-91854

cve-icon Vulnrichment

Updated: 2026-09-22T15:34:09.225Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T17:17:39.680

Modified: 2026-09-22T16:18:08.637

Link: CVE-2026-91854

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:45:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')