PT-2022-26741 · Unknown · Web-Based Student Clearance System

·

CVE-2022-43078

·

Published

2022-11-01

·

Updated

2025-05-05

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Web-Based Student Clearance System version 1.0
Description A cross-site scripting (XSS) issue exists in the /admin/add-fee.php endpoint, allowing attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cmddept parameter.
Recommendations For Web-Based Student Clearance System version 1.0, consider disabling access to the /admin/add-fee.php endpoint or restricting the use of the cmddept parameter until a patch is available. Avoid using the cmddept parameter in the affected endpoint until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-43078

Affected Products

Web-Based Student Clearance System