A vulnerability labeled as problematic has been found in code-projects Exam Form Submission 1.0. This vulnerability affects unknown code of the file /admin/update_s6.php. Executing a manipulation of the argument sname can lead to cross site scripting.

This vulnerability is tracked as CVE-2026-4595. The attack can be launched remotely. Moreover, an exploit is present.