Record summary

CVE-2019-14696 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBOpen-School 3.0 / Community Edition 2.3 - Cross-Site ScriptingExploitDB exploitby Greg.PriestNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMOpen-School 3.0/Community Edition 2.3 - Cross-Site ScriptingCVSS 6.1

Open-School 3.0, and Community Edition 2.3, allows cross-site scripting via the osv/index.php?r=students/guardians/create id parameter.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.

Remediation

To remediate this issue, it is recommended to implement proper input validation and sanitization techniques to prevent the execution of malicious scripts.

WeaknessesCWE-79
Authorspikpikcu
Template tagscvecve2019xssopen-schoolpacketstormvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:open-school:open-school:2.3:*:*:*:community:*:*:*

Source: ProjectDiscovery

References

4