๐Ÿ” CVE Alert

CVE-2026-96810

LOW 3.5

huanzi-qch base-admin Add User CommonController.java save cross site scripting

CVSS Score
3.5
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was identified in huanzi-qch base-admin up to 52816b760cd53244989fd664bbb2b3d4edbfdbf1. This issue affects the function Save of the file base-admin-master\src\main\java\cn\huanzi\qch\baseadmin\common\controller\CommonController.java of the component Add User Handler. The manipulation of the argument Username leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.

CWE CWE-79 CWE-94
Vendor huanzi-qch
Product base-admin
Published Sep 24, 2026
Stay Ahead of the Next One

Get instant alerts for huanzi-qch base-admin

Be the first to know when new low vulnerabilities affecting huanzi-qch base-admin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

huanzi-qch / base-admin
52816b760cd53244989fd664bbb2b3d4edbfdbf1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/409062 vuldb.com: https://vuldb.com/vuln/409062/cti vuldb.com: https://vuldb.com/cve/CVE-2026-96810 vuldb.com: https://vuldb.com/submit/905724 github.com: https://github.com/jac40577-art/cve-db/blob/master/BaseAdminSystem%20-%20Introduction_to_Storage-Based_XSS_Vulnerability.md

Credits

๐Ÿ” Jacinta (VulDB User) VulDB CNA Team