CVE-2026-4991 | QDOCS Smart School Management System up to 7.2 Admission Enquiry /admin/enquiry Note cross site scripting
A vulnerability classified as problematic has been found in QDOCS Smart School Management System up to 7.2. The impacted element is an unknown function of the file /admin/enquiry of the component Admission Enquiry Module. Performing a manipulation of the argument Note results in cross site scripting.
This vulnerability is reported as CVE-2026-4991. The attack is possible to be carried out remotely. No exploit exists.