PT-2025-3953 · Unknown · Campcodes School Management

Khukuririmal

·

Published

2025-01-18

·

Updated

2025-01-18

·

CVE-2025-0560

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CampCodes School Management Software version 1.0
Description A problematic vulnerability was found in the Photo Gallery Page component of the software, specifically in an unknown function of the file /photo-gallery. The manipulation of the Description argument leads to cross-site scripting. This issue can be launched remotely. An exploit has been publicly disclosed, making it possible for attackers to use it.
Recommendations For CampCodes School Management Software version 1.0, consider disabling the Photo Gallery Page component or restricting access to the /photo-gallery file until a patch is available. As a temporary workaround, avoid using the Description argument in the affected component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-0560

Affected Products

Campcodes School Management