What is CVE-2026-19998?
A cross-site scripting (XSS) vulnerability has been identified in code-projects Online Shopping System 1.0, affecting the offersmail.php file via manipulation of the email argument. The vulnerability allows remote attacks and has a publicly available exploit, requiring immediate input sanitization measures.
Azərbaycanca: code-projects Online Shopping System 1.0 proqramının offersmail.php faylında, email arqumentinin manipulyasiyası ilə uzaqdan XSS (Cross Site Scripting) hücumuna imkan verən zəiflik aşkar edilib. İstismar kodu ictimaiyyətə açıq olduğu üçün təcili olaraq daxil edilən məlumatların filtirlənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: code-projects
FAQ2
What system does the CVE-2026-19998 vulnerability affect?
This vulnerability affects code-projects Online Shopping System 1.0.
How is an attack carried out using the CVE-2026-19998 vulnerability?
The attack is conducted remotely via XSS by manipulating the email argument in the offersmail.php file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.