CVE-2026-5643Disclosure

LOWCVSS 1.9 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This impacts an unknown function of the file /admin/Add%20notice/notice.php of the component Admin Add Endpoint. Such manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-06: 3Technical Details · 2026-04-06: 104-06
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5643 Cross Site Scripting in Cyber-III Student-Management-System Admin Add Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5643

    Post summary

    The post announces a new XSS vulnerability (CVE-2026-5643) affecting the Cyber-III Student-Management-System admin add endpoint, with no further exploit or patch information provided.

    0000052
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-5643 A vulnerability was identified in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This impacts an unknown function of the file /admi… https://www.cve.org/CVERecord?id=CVE-2026-5643 ----- Traducción: CVE-2026-5643 Se … http://infoflow.cloud`

    Post summary

    The post references a new CVE (CVE‑2026‑5643) but offers no specific technical details, exploit code, or mitigation information.

    0000034
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5643 A vulnerability was identified in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This impacts an unknown function of the file /admi… https://www.cve.org/CVERecord?id=CVE-2026-5643

    Post summary

    CVE-2026-5643 is a newly identified vulnerability affecting an unknown function of the file /admi… in Cyber-III Student-Management-System, with no further details on exploitation, mitigation, or technical specifics provided.

    00000273
    57.0K followersView on X

Explore more