CVE-2026-91854

Summary

A vulnerability was identified in code-projects Record Management System 1.0. Affected is an unknown function of the file main/reg.php. Such manipulation of the argument desc leads to cross site scripting. The attack may be launched remotely. The exploit is publicly available and might be used.

Affected Software

VendorProductVersion RangeStatus
code-projectsRecord Management System1.0affected

Weaknesses

  • CWE-79: Cross Site Scripting
  • CWE-94: Code Injection

References