CVE-2019-14696
MEDIUM NUCLEIOpen-School 3.0 and Community Edition 2.3 - Cross-Site Scripting via Guardians Create ID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-14696. PoCs published by Greg.Priest. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in Open-School 3.0 and Community Edition 2.3 via the 'id' parameter in the /index.php?r=students/guardians/create endpoint. The PoC shows how arbitrary JavaScript can be injected and executed in the context of the victim's browser.
Description
Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter.
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in Open-School 3.0 and Community Edition 2.3 via the 'id' parameter in the /index.php?r=students/guardians/create endpoint. The PoC shows how arbitrary JavaScript can be injected and executed in the context of the victim's browser.
Nuclei Templates (1)
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N