Description
A vulnerability has been found in code-projects Project Management System 1.0. This vulnerability affects unknown code of the file /mail.php of the component Mail Compose Page. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
Severity (CVSS)
| Base score | 5.1 |
|---|---|
| Severity | Medium |
| Version | CVSS 4.0 |
| Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P |
| Provided by | CNA |
Weaknesses
- CWE-79 — Cross Site Scripting
- CWE-94 — Code Injection
Affected products
| Vendor | Product | Versions |
|---|---|---|
| code-projects | Project Management System | 1.0 |
References
- https://vuldb.com/vuln/374499 (vdb-entry)
- https://vuldb.com/vuln/374499/cti (signature permissions-required)
- https://vuldb.com/cve/CVE-2026-13504 (third-party-advisory)
- https://vuldb.com/submit/838683 (third-party-advisory)
- https://github.com/MyMySSS/CVE123/blob/main/cve4/PMS_CVE_Submission.md (exploit)
- https://code-projects.org/ (product)
Generated from the official CVE List on 29 Jun 2026 07:08 UTC.