Cross Site Scripting Vulnerability in Follet School Solutions Destiny Products
CVE-2023-38827

6.1MEDIUM

Key Information:

Vendor
CVE Published:
9 January 2024

What is CVE-2023-38827?

A Cross Site Scripting vulnerability has been identified in the Follet School Solutions Destiny product, specifically affecting version 20_0_1_AU4 and later. This vulnerability enables a remote attacker to exploit the application via the presentonesearchresultsform.do endpoint, potentially allowing for arbitrary code execution. It poses a significant risk for users, highlighting the importance of implementing robust security measures and keeping products updated to protect sensitive educational data.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.