CVE-2026-102292 Details
Description
A flaw has been found in coolbeans1212 MateisHomePage-Website up to ea2a4226deeca27ab1fb9df0552ec76444547811. Affected by this issue is some unknown functionality of the file users.php. This manipulation of the argument Search causes cross site scripting. The attack can be initiated remotely. The exploit has been published and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. Patch name: 6406308df9771d2fd477b56dafe4878dd846df6e. Applying a patch is the recommended action to fix this issue.
A cross-site scripting (XSS) vulnerability exists in the Coolbeans1212 MateisHomepage Website in the file users.php, prior to commit ea2a4226deeca27ab1fb9df0552ec76444547811. The issue arises from improper sanitization of the 'search' parameter, allowing remote attackers to inject malicious scripts that are executed in the context of the user's browser session.
A patch has been applied in commit 6406308df9771d2fd477b56dafe4878dd846df6e, which addresses the vulnerability by properly sanitizing the 'search' parameter input.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/coolbeans1212/MateisHomePage-Website/ | [email protected] | Source CodeVendor |
| https://github.com/coolbeans1212/MateisHomePage-Website/commit/6406308df9771d2fd477b56dafe4878dd846df6e | [email protected] | Source CodeVendor |
| https://github.com/coolbeans1212/MateisHomePage-Website/issues/8 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/cve/CVE-2026-102292 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/940461 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/411182 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/411182/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| coolbeans1212 MateisHomePage-Website | <ea2a4226deeca27ab1fb9df0552ec76444547811> |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion