PT-2024-25624 · Unknown · School Management System

·

CVE-2024-33992

·

Published

2024-08-06

·

Updated

2024-08-15

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions School Event Management System version 1.0
Description A Cross-Site Scripting (XSS) issue affects the system, allowing an attacker to exploit it by sending a specially crafted query to the server. This can lead to the retrieval of all stored information through the view parameter in the "/student/index.php" API endpoint.
Recommendations For School Event Management System version 1.0, consider disabling the view parameter in the "/student/index.php" endpoint until a patch is available to prevent exploitation. Restrict access to this endpoint to minimize the risk of information retrieval.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-33992

Affected Products

School Management System