Cross Site Scripting Vulnerability in Campcodes Online Student Management System 1.0
CVE-2024-3531
Summary
A cross-site scripting vulnerability exists in the Campcodes Complete Online Student Management System, specifically affecting the courses_view.php file. This vulnerability allows attackers to manipulate the FirstRecord argument, enabling the execution of malicious scripts in users' browsers. The exploitation of this vulnerability can be executed remotely, potentially compromising user data and session integrity. With public disclosure of the exploit, it is crucial for users and administrators of affected systems to implement necessary security measures to mitigate risks associated with this vulnerability.
Affected Version(s)
Complete Online Student Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved