PT-2022-24676 · Schoolbox Pty+1 · Schoolbox

Nelson Fernandes

·

Published

2022-10-31

·

Updated

2023-10-25

·

CVE-2022-39020

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions No specific software or versions mentioned.
Description The application is affected by multiple instances of cross-site scripting (XSS), including both stored and reflected XSS. Vulnerable features include student assessment submission, file upload, news, ePortfolio, and calendar event creation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-39020

Affected Products

Schoolbox