PT-2022-10231 · Unknown · Student Management System
Published
2022-07-27
·
Updated
2025-04-22
·
CVE-2021-33371
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Student Management System version 1.0
Description
A stored cross-site scripting (XSS) issue in the "/nav bar action.php" API endpoint allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the
Chat box. This enables the execution of malicious code on the client-side.Recommendations
For Student Management System version 1.0, consider disabling the
/nav bar action.php endpoint or restricting access to it until a proper fix is applied, and ensure proper input validation and sanitization for the Chat box to prevent malicious payload injection.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Student Management System