PT-2024-22262 · Schoolbox · Schoolbox

Akshay Raj

·

Published

2024-03-07

·

Updated

2024-03-07

·

CVE-2024-28095

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Schoolbox versions prior to 23.1.3
Description The issue concerns stored cross-site scripting in the news functionality, allowing an authenticated attacker to perform security actions in the context of affected users.
Recommendations For versions prior to 23.1.3, update to version 23.1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the news functionality until a patch is applied. Avoid using the news functionality in a way that could allow an attacker to inject malicious scripts.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-28095

Affected Products

Schoolbox