Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Dylan Davis

#22203of 53,634
10.2Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-44212
5.1
2026-05-28
Follet School Solutions · Destiny · CVE-2024-47096
**Name of the Vulnerable Software and Affected Versions** Follet School Solutions Destiny versions prior to 22.0.1 AU1 **Description** A Cross Site Scripting issue allows a remote attacker to execute arbitrary client-side code. This is achieved through the `showSupportExpiredMessage` parameter of the 'handleloginform.do' endpoint. **Recommendations** Update to version 22.0.1 AU1 or later. As a temporary workaround, restrict access to the 'handleloginform.do' endpoint or avoid using the `showSupportExpiredMessage` parameter.
PT-2026-44213
5.1
2026-05-28
Follet School Solutions · Destiny · CVE-2024-47097
Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a remote attacker to run arbitrary client-side code via the site parameter of handleloginform.do.