PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-93975 code-projects CVE debrief

A vulnerability was found in code-projects Assessment Management 1.0, specifically in the admin/edit-user.php file of the User Editing component. The manipulation of certain arguments leads to cross-site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability impacts the confidentiality, integrity, and availability of the system. Defenders should assess the exposure of their systems and prioritize verification and remediation efforts.

Vendor
code-projects
Product
Assessment Management
CVSS
LOW 1.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-20
Original CVE updated
2026-09-20
Advisory published
2026-09-20
Advisory updated
2026-09-20

Who should care

Defenders responsible for code-projects Assessment Management 1.0 systems should assess exposure and prioritize verification and remediation efforts. This includes reviewing the system's configuration, identifying potential entry points, and implementing patches or mitigations as available. Additionally, defenders should monitor systems for potential exploitation attempts and review compensating controls for exposed systems.

Why it matters

Defenders should care about CVE-2026-93975 because it is a cross-site scripting vulnerability in code-projects Assessment Management 1.0 that may allow remote exploitation. Affected systems should be identified and patched or mitigated to prevent potential attacks. The exploit has been disclosed to the public and may be used.

  • Verify potential exposure to cross-site scripting attacks
  • Assess the risk of remote exploitation
  • Prioritize patching or mitigation efforts for affected systems
  • Monitor systems for potential exploitation attempts

Technical summary

The vulnerability is located in the admin/edit-user.php file of the User Editing component in code-projects Assessment Management 1.0. The manipulation of certain arguments (name, sname, email, username, password, id) leads to cross-site scripting. The attack may be initiated remotely. The vulnerability impacts the confidentiality, integrity, and availability of the system. Defenders should assess the exposure of their systems and prioritize verification and remediation efforts. The exploit has been disclosed to the public and may be used.

Defensive priority

Defenders should prioritize verifying the presence of this vulnerability in their systems and applying patches or mitigations as available.

Recommended defensive actions

  • Verify the presence of this vulnerability in code-projects Assessment Management 1.0 systems
  • Apply patches or mitigations as available
  • Monitor systems for potential exploitation attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide information on the vulnerability, but details on affected versions, exploitation, and remediation are limited. The exploit has been disclosed to the public and may be used. There is no information on publicly available exploits. The vulnerability is located in the admin/edit-user.php file of the User Editing component in code-projects Assessment Management 1.0.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-93975 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-93975

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-93975 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93975

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.