Cross-Site Scripting in School ERP Pro+Responsive by Arox Solutions
CVE-2024-4823

Currently unrated

Key Information:

Vendor
CVE Published:
14 May 2024

What is CVE-2024-4823?

The School ERP Pro+Responsive 1.0 application contains a Cross-Site Scripting (XSS) vulnerability that can be exploited through the index page at '/schoolerp/office_admin/'. Several parameters, including es_bankacc, es_bank_name, es_bank_pin, es_checkno, es_teller_number, dc1, and dc2, can be manipulated by an attacker. By sending a specifically crafted JavaScript payload to an authenticated user, an attacker can compromise the user's browser session, leading to potential unauthorized access and data exposure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability published

.