CVE-2026-32844

XinLiangCoder php_api_doc through commit 1ce5bbf contains a reflected cross-site scripting vulnerability in list_method.php that allows remote attackers to execute arbitrary JavaScript in a victim's browser by injecting malicious code through the f parameter. Attackers can craft a malicious URL with unsanitized input in the GET request parameter that is output directly to the page without proper neutralization, enabling session hijacking, credential theft, or malware distribution within the application context.
Configurations

Configuration 1 (hide)

cpe:2.3:a:xinliangcoder:php_api_doc:*:*:*:*:*:*:*:*

History

14 Apr 2026, 01:19

Type Values Removed Values Added
References () https://github.com/XinLiangCoder/php_api_doc/tree/1ce5bbf1429c077d6e3f0860098099d272e3f3c2 - () https://github.com/XinLiangCoder/php_api_doc/tree/1ce5bbf1429c077d6e3f0860098099d272e3f3c2 - Patch
References () https://www.vulncheck.com/advisories/xinliangcoder-php-api-doc-reflected-xss-via-list-method-php - () https://www.vulncheck.com/advisories/xinliangcoder-php-api-doc-reflected-xss-via-list-method-php - Third Party Advisory, VDB Entry
First Time Xinliangcoder php Api Doc
Xinliangcoder
CPE cpe:2.3:a:xinliangcoder:php_api_doc:*:*:*:*:*:*:*:*
Summary
  • (es) XinLiangCoder php_api_doc a través del commit 1ce5bbf contiene una vulnerabilidad de cross-site scripting reflejado en list_method.php que permite a atacantes remotos ejecutar JavaScript arbitrario en el navegador de una víctima inyectando código malicioso a través del parámetro f. Los atacantes pueden crear una URL maliciosa con entrada no saneada en el parámetro de solicitud GET que se muestra directamente en la página sin la neutralización adecuada, lo que permite el secuestro de sesión, el robo de credenciales o la distribución de malware dentro del contexto de la aplicación.

20 Mar 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-20 18:16

Updated : 2026-04-14 01:19


NVD link : CVE-2026-32844

Mitre link : CVE-2026-32844

CVE.ORG link : CVE-2026-32844


JSON object : View

Products Affected

xinliangcoder

  • php_api_doc
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')