Vulnerability Details CVE-2024-4823
Vulnerability in School ERP Pro+Responsive 1.0 that allows XSS via the index '/schoolerp/office_admin/' in the parameters es_bankacc, es_bank_name, es_bank_pin, es_checkno, es_teller_number, dc1 and dc2. An attacker could send a specially crafted JavaScript payload to an authenticated user and partially hijack their browser session.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 56.8%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2024-4823
-
cpe:2.3:a:arox:school_erp_pro+responsive:1.0