Cross-Site Scripting Vulnerability in OpenSIS Community Edition by OS4ED
CVE-2021-40310

5.4MEDIUM

Key Information:

Vendor

Os4ed

Status
Vendor
CVE Published:
24 September 2021

What is CVE-2021-40310?

The OpenSIS Community Edition version 8.0 has a cross-site scripting (XSS) vulnerability that occurs in the TakeAttendance.php file via the cp_id_miss_attn parameter. This flaw allows an attacker to inject malicious scripts into the web application, potentially leading to unauthorized actions or data exposure within the affected environment.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.