CVE-2026-3043 - Vulnerability Analysis
MediumCVSS: 4.3Last Updated: February 24, 2026
itsourcecode Event Management System - Reflected XSS
Published: February 24, 2026Updated: February 24, 2026PoC AvailableRemote Exploitable
Overview
itsourcecode Event Management System 1.0 contains a reflected XSS caused by manipulation of the "page" argument in /admin/navbar.php, letting remote attackers execute scripts, exploit requires crafted request.
Severity & Score
Severity: Medium
CVSS Score: 4.3
Impact
Remote attackers can execute arbitrary scripts in users' browsers, potentially stealing session data or performing actions on behalf of users.
Mitigation
Update to the latest version.
References
Related Resources
Details
- CVE ID
- CVE-2026-3043
- Severity
- Medium
- CVSS Score
- 4.3
- Type
- reflected_xss
- Status
- confirmed
CWE
- CWE-79
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N