A vulnerability was found in code-projects Exam Form Submission 1.0/7.php. It has been classified as problematic. This impacts an unknown function of the file /admin/update_s7.php. This manipulation of the argument sname causes cross site scripting.
The identification of this vulnerability is CVE-2026-4909. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.