PT-2022-14138 · Unknown · Student Information System

Webraybtl

·

Published

2022-05-24

·

Updated

2022-06-02

·

CVE-2022-1819

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Student Information System version 1.0
Description A problematic issue was found in the Student Information System, affecting the "admin/?page=students" endpoint of the Student Roll module. The manipulation with the input <script>alert(1)</script> leads to authenticated cross-site scripting. Exploit details have been disclosed to the public.
Recommendations For Student Information System version 1.0, consider disabling the admin/?page=students endpoint of the Student Roll module until a patch is available. Restrict access to this module to minimize the risk of exploitation. Avoid using malicious input in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1819

Affected Products

Student Information System