LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-3043 - Vulnerability Analysis

MediumCVSS: 4.3

Last Updated: February 24, 2026

itsourcecode Event Management System - Reflected XSS

Published: February 24, 2026Updated: February 24, 2026PoC AvailableRemote Exploitable

Overview

itsourcecode Event Management System 1.0 contains a reflected XSS caused by manipulation of the "page" argument in /admin/navbar.php, letting remote attackers execute scripts, exploit requires crafted request.

Severity & Score

Severity: Medium
CVSS Score: 4.3

Impact

Remote attackers can execute arbitrary scripts in users' browsers, potentially stealing session data or performing actions on behalf of users.

Mitigation

Update to the latest version.

Details

CVE ID
CVE-2026-3043
Severity
Medium
CVSS Score
4.3
Type
reflected_xss
Status
confirmed

CWE

  • CWE-79

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N