PT-2026-44212 · Follet School Solutions · Destiny

Dylan Davis

·

Published

2026-05-28

·

Updated

2026-05-28

·

CVE-2024-47096

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Follet School Solutions Destiny versions prior to 22.0.1 AU1
Description A Cross Site Scripting issue allows a remote attacker to execute arbitrary client-side code. This is achieved through the showSupportExpiredMessage parameter of the 'handleloginform.do' endpoint.
Recommendations Update to version 22.0.1 AU1 or later. As a temporary workaround, restrict access to the 'handleloginform.do' endpoint or avoid using the showSupportExpiredMessage parameter.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-47096

Affected Products

Destiny