CVE-2026-9377
published 2026-05-24CVE-2026-9377: A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of the file /admin/productedit.php. The…
PriorityP414low2.4CVSS 3.1
AVNACLPRHUIRSUCNILAN
EPSS
0.20%
10.2th percentile
A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of the file /admin/productedit.php. The manipulation of the argument productName leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sourcecodester | sup_online_shopping | — | — |
CVSS provenance
nvdv3.12.4LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
nvdv4.01.9LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.03.3LOWAV:N/AC:L/Au:M/C:N/I:P/A:N
cvelistv5v4.04.8MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
yt-dlp: File Downloader cookie leak with curl
ghsa·2026-06-16
CVE-2026-50019 [MEDIUM] CWE-200 yt-dlp: File Downloader cookie leak with curl
yt-dlp: File Downloader cookie leak with curl
### Summary
If curl is used an external downloader for yt-dlp, cookies may be leaked to an unintended host upon HTTP redirect or when the host for download fragments differs from their parent manifest's.
This is the equivalent to [GHSA-v8mc-9377-rwjj]() for the `curl` downloader. The vulnerable behavior is present in [yt-dlp](https://github.com/yt-dlp/yt-dlp) released since 2023.09.24.
### Details
At the file download stage, the cookies are passed by yt-dlp to the file downloader via `--cookie`. However, unless these are loaded from a file, this operation does not activate the cookie engine. As a result, `curl` will send cookies with requests to domains or paths for which the cookies are not scoped.
An example of a potential attack scenario
GHSA
GHSA-29h5-px7p-c3gq: A vulnerability was identified in SourceCodester SUP Online Shopping 1
ghsa_unreviewed·2026-05-26
CVE-2026-9377 [LOW] CWE-79 GHSA-29h5-px7p-c3gq: A vulnerability was identified in SourceCodester SUP Online Shopping 1
A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of the file /admin/productedit.php. The manipulation of the argument productName leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
CVEList
SourceCodester SUP Online Shopping productedit.php cross site scripting
cvelistv5·2026-05-24·CVSS 4.8
CVE-2026-9377 [MEDIUM] CWE-79 SourceCodester SUP Online Shopping productedit.php cross site scripting
SourceCodester SUP Online Shopping productedit.php cross site scripting
A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of the file /admin/productedit.php. The manipulation of the argument productName leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
Timeline: 2026-05-23: Advisory disclosed; 2026-05-23: VulDB entry created; 2026-05-23: VulDB entry last update
VulDB
SourceCodester SUP Online Shopping 1.0 /admin/productedit.php productName cross site scripting
vuldb·2026-05-23
CVE-2026-9377 [LOW] SourceCodester SUP Online Shopping 1.0 /admin/productedit.php productName cross site scripting
A vulnerability identified as problematic has been detected in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of the file /admin/productedit.php. The manipulation of the argument productName leads to cross site scripting.
This vulnerability is traded as CVE-2026-9377. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-24
Published