PT-2025-35084 · Unknown · Projectsandprograms School Management System
Jairajparyani
·
Published
2025-08-28
·
Updated
2025-08-28
·
CVE-2025-51967
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ProjectsAndPrograms School Management System version 1.0
Description
A Reflected Cross-site Scripting (XSS) issue exists in the
themeSet.php file. The application does not properly sanitize user-supplied input in the theme parameter, which allows an attacker to inject and execute arbitrary JavaScript in a victim’s browser.Recommendations
As a temporary workaround, consider restricting access to the
themeSet.php file until a fix is available.
Ensure proper sanitization of the theme parameter to prevent the injection of malicious scripts.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Projectsandprograms School Management System