PT-2025-3953 · Unknown · Campcodes School Management
Khukuririmal
·
Published
2025-01-18
·
Updated
2025-01-18
·
CVE-2025-0560
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
CampCodes School Management Software version 1.0
Description
A problematic vulnerability was found in the Photo Gallery Page component of the software, specifically in an unknown function of the file /photo-gallery. The manipulation of the
Description argument leads to cross-site scripting. This issue can be launched remotely. An exploit has been publicly disclosed, making it possible for attackers to use it.Recommendations
For CampCodes School Management Software version 1.0, consider disabling the Photo Gallery Page component or restricting access to the /photo-gallery file until a patch is available. As a temporary workaround, avoid using the
Description argument in the affected component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Campcodes School Management