PT-2024-22263 · Schoolbox · Schoolbox

Akshay Raj

·

Published

2024-03-07

·

Updated

2024-03-07

·

CVE-2024-28096

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Schoolbox versions prior to 23.1.3
Description The issue concerns stored cross-site scripting in the Class functionality of the Schoolbox application. This allows an authenticated attacker to perform security actions in the context of affected users.
Recommendations For versions prior to 23.1.3, update to version 23.1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the Class functionality to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-28096

Affected Products

Schoolbox