What is CVE-2026-19904?
A cross-site scripting (XSS) vulnerability was found in the System Settings Module (/admin/index.php?page=site_settings) of SourceCodester Online Book Store System 1.0. This issue allows remote code execution via manipulation of unknown parameters. Affected systems should be patched immediately.
Azərbaycanca: SourceCodester Online Book Store System 1.0-da System Settings Module-i (/admin/index.php?page=site_settings) vasitəsilə cross site scripting (XSS) zəifliyi aşkar edilib. Bu zəiflik uzaqdan hücuma imkan verir. Təsirlənmiş sistemlərdə dərhal patç tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: SourceCodester
FAQ1
Which specific module in SourceCodester Online Book Store System 1.0 is affected by the XSS vulnerability?
The vulnerability was found in the System Settings Module, specifically via the /admin/index.php?page=site_settings file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.