A vulnerability was found in code-projects Exam Form Submission 1.0. It has been classified as problematic. The affected element is an unknown function of the file /admin/update_s4.php. Performing a manipulation of the argument sname results in cross site scripting.

This vulnerability was named CVE-2026-4577. The attack may be initiated remotely. In addition, an exploit is available.