CVE-2019-14696
MEDIUMNuclei
Open-School 3.0 / Community Edition 2.3 - Cross-Site Scripting
Record summary
CVE-2019-14696 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Proofs of concept
1Catalogued exploits
ExploitDBOpen-School 3.0 / Community Edition 2.3 - Cross-Site ScriptingExploitDB exploitby Greg.PriestNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMOpen-School 3.0/Community Edition 2.3 - Cross-Site ScriptingCVSS 6.1
Open-School 3.0, and Community Edition 2.3, allows cross-site scripting via the osv/index.php?r=students/guardians/create id parameter.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.
Remediation
To remediate this issue, it is recommended to implement proper input validation and sanitization techniques to prevent the execution of malicious scripts.
WeaknessesCWE-79
Authorspikpikcu
Template tagscvecve2019xssopen-schoolpacketstormvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:open-school:open-school:2.3:*:*:*:community:*:*:*
https://open-school.org/ https://pastebin.com/AgxqdbAQ http://packetstormsecurity.com/files/153984/Open-School-3.0-Community-Edition-2.3-Cross-Site-Scripting.html https://nvd.nist.gov/vuln/detail/CVE-2019-14696 https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
4packetstormsecurity.com
http://packetstormsecurity.com/files/153984/Open-School-3.0-Community-Edition-2.3-Cross-Site-Scripting.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-14696 open-school.org
https://open-school.org/ pastebin.com
https://pastebin.com/AgxqdbAQ