PT-2025-3953 · Unknown · Campcodes School Management

Khukuririmal

·

Publicado

2025-01-18

·

Atualizado

2025-01-18

·

CVE-2025-0560

CVSS v3.1

4.8

Média

VetorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CampCodes School Management Software version 1.0
Description A problematic vulnerability was found in the Photo Gallery Page component of the software, specifically in an unknown function of the file /photo-gallery. The manipulation of the Description argument leads to cross-site scripting. This issue can be launched remotely. An exploit has been publicly disclosed, making it possible for attackers to use it.
Recommendations For CampCodes School Management Software version 1.0, consider disabling the Photo Gallery Page component or restricting access to the /photo-gallery file until a patch is available. As a temporary workaround, avoid using the Description argument in the affected component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-0560

Produtos afetados

Campcodes School Management