vendor:
Free School Management Software
by:
fuzzyap1
9.3
CVSS
CRITICAL
Stored Cross-Site Scripting (XSS)
79
CWE
Product Name: Free School Management Software
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE: a:sourcecodester:free_school_management_software
Platforms Tested: Windows
2021
Free School Management Software 1.0 – ‘multiple’ Stored Cross-Site Scripting (XSS)
A stored XSS vulnerability exists in the Event management software. An attacker can leverage this vulnerability in order to run javascript on the web server surfers behalf, which can lead to cookie stealing, defacement and more.
Mitigation:
Input validation and output encoding can be used to mitigate XSS attacks.