Stored Cross-Site Scripting (XSS) was found in the /admin/edit_user.php page of Society Management System Portal V1.0, which allows remote attackers to inject and store arbitrary JavaScript code that is executed in users' browsers. This vulnerability can be exploited via the name parameter in a POST HTTP request, leading to execution of malicious scripts when the affected content is viewed by other users, including administrators.
References
| Link | Resource |
|---|---|
| https://github.com/0xBhushan/Writeups/blob/main/CVE/Kashipara/Society%20Management%20System%20Portal/Stored%20XSS-name.pdf | Exploit Third Party Advisory |
Configurations
History
26 Feb 2026, 20:02
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-79 | |
| CPE | cpe:2.3:a:kashipara:society_management_system_portal:1.0:*:*:*:*:*:*:* | |
| Summary |
|
|
| First Time |
Kashipara
Kashipara society Management System Portal |
|
| References | () https://github.com/0xBhushan/Writeups/blob/main/CVE/Kashipara/Society%20Management%20System%20Portal/Stored%20XSS-name.pdf - Exploit, Third Party Advisory |
23 Feb 2026, 19:22
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
23 Feb 2026, 18:25
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-23 18:25
Updated : 2026-02-26 23:16
NVD link : CVE-2026-26464
Mitre link : CVE-2026-26464
CVE.ORG link : CVE-2026-26464
JSON object : View
Products Affected
kashipara
- society_management_system_portal
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
