huang-yk

2 exploits Active since Mar 2025
CVE-2024-13902 GITEE LOW
huang-yk student-manage 1.0 - Cross-Site Scripting via Class Parameter
A vulnerability, which was classified as problematic, was found in huang-yk student-manage 1.0. This affects an unknown part of the component Edit a Student Information Page. The manipulation of the argument Class leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
10 stars
CVSS 2.4
CVE-2025-29504 GITEE HIGH
student-manage 1 - Privilege Escalation via Unsafe Permission Verification
Insecure Permission vulnerability in student-manage 1 allows a local attacker to escalate privileges via the Unsafe permission verification.
10 stars
CVSS 7.8