Cross-Site Scripting Vulnerability in ZeroWdd StudentManager 1.0
CVE-2024-13143
5.1MEDIUM
What is CVE-2024-13143?
A cross-site scripting vulnerability exists in ZeroWdd StudentManager 1.0, specifically within the submitAddPermission function of the PermissionController.java file. This vulnerability stems from improper handling of the argument 'url', allowing an attacker to inject malicious scripts that may be executed when targeted users interact with the application. The attack can be carried out remotely, and the disclosed exploit poses a significant risk as other parameters could also be susceptible. It's crucial for organizations using this application to address this issue promptly to mitigate potential exploitation.
Affected Version(s)
studentmanager 1.0