Unknown · Base-Admin · CVE-2026-96810
**Name of the Vulnerable Software and Affected Versions**
huanzi-qch base-admin versions up to 52816b760cd53244989fd664bbb2b3d4edbfdbf1
**Description**
A remote cross site scripting issue exists in the Add User Handler component. The problem occurs within the `Save()` function located in the `base-admin-mastersrcmainjavacnhuanziqchbaseadmincommoncontrollerCommonController.java` file. An attacker can trigger this by manipulating the `Username` variable.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the `Save()` function or sanitize the `Username` input to minimize the risk of exploitation.