Cross-Site Scripting Vulnerability in ZeroWdd StudentManager 1.0
CVE-2024-13143

5.1MEDIUM

Key Information:

Vendor

Zerowdd

Vendor
CVE Published:
6 January 2025

What is CVE-2024-13143?

A cross-site scripting vulnerability exists in ZeroWdd StudentManager 1.0, specifically within the submitAddPermission function of the PermissionController.java file. This vulnerability stems from improper handling of the argument 'url', allowing an attacker to inject malicious scripts that may be executed when targeted users interact with the application. The attack can be carried out remotely, and the disclosed exploit poses a significant risk as other parameters could also be susceptible. It's crucial for organizations using this application to address this issue promptly to mitigate potential exploitation.

Affected Version(s)

studentmanager 1.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

Credit

LVZC1 (VulDB User)
.