CVE-2026-6486 Details
Description
A vulnerability was detected in classroombookings up to 2.17.0. This impacts the function read of the file crbs-core/application/views/layout.php of the component User Display Name Handler. The manipulation of the argument displayname results in cross site scripting. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version 2.17.1 will fix this issue. The patch is identified as 69c3c9bb8a17f1ea572d8f4502bf238f0214c98a. It is suggested to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
A stored cross-site scripting vulnerability has been identified in Classroombookings versions prior to 2.17.0. The issue resides in the User Display Name Handler, specifically within the 'read' function of 'crbs-core/application/views/layout.php'. This vulnerability allows authenticated users with the Teacher role to inject malicious JavaScript into the Display Name field, which is then executed when the profile data is viewed. The vulnerability can be exploited remotely, and a public exploit is available.
Users are advised to upgrade to Classroombookings version 2.17.1, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 17, 2026CISA-ADP
Assessed Apr 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/classroombookings/classroombookings/ | [email protected] | Source CodeVendor |
| https://github.com/classroombookings/classroombookings/commit/69c3c9bb8a17f1ea572d8f4502bf238f0214c98a | [email protected] | Source CodeVendor |
| https://github.com/classroombookings/classroombookings/pull/83 | [email protected] | Issue TrackingVendor |
| https://github.com/classroombookings/classroombookings/releases/tag/v2.17.1 | [email protected] | Release NotesVendor |
| https://github.com/sudo-secure/security-research/blob/main/classroombookings/stored-xss/PoC.md | [email protected] | ExploitTechnical Description |
| https://vuldb.com/submit/786154 | [email protected] | Technical Description |
| https://vuldb.com/vuln/358027 | [email protected] | AdvisoryExploitRemedy |
| https://vuldb.com/vuln/358027/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| classroombookings | <= 2.17.0 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Apr 17, 2026 | New CVE Received | [email protected] |
Volerion