cert.plThird-party advisory
https://cert.pl/posts/2026/06/CVE-2026-34906 CVE-2026-34907
MEDIUM
Reflected Cross-Site Scripting (XSS) in Wirtualna Uczelnia
Record summary
CVE-2026-34907 has a selected CVSS score of 5.1 (medium).
Description
Wirtualna Uczelnia is vulnerable to Reflected Cross‑Site Scripting (XSS) due to insecure handling of the locale parameter across multiple endpoints. An attacker can craft a malicious URL with JavaScript embedded in the locale parameter and send it to a victim. When the victim opens the link, the injected script will be executed in their browser. This issue affects Wirtualna Uczelnia versions up to wu#2016.437.295#0#20260327_105545
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 2, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Wirtualna UczelniaBrowse Simple SA / Wirtualna UczelniaDefault status: unaffected | CVE List | Through wu#2016.437.295#0#20260327_105545 | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-34907 simple.com.plproduct
https://simple.com.pl/branze/edukacyjna