Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3p6p-6hwj-52g9

Опубликовано: 28 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

A Reflected Cross-site Scripting (XSS) vulnerability exists in the themeSet.php file of ProjectsAndPrograms School Management System 1.0. The application fails to sanitize user-supplied input in the theme POST parameter, allowing an attacker to inject and execute arbitrary JavaScript in a victim's browser.

A Reflected Cross-site Scripting (XSS) vulnerability exists in the themeSet.php file of ProjectsAndPrograms School Management System 1.0. The application fails to sanitize user-supplied input in the theme POST parameter, allowing an attacker to inject and execute arbitrary JavaScript in a victim's browser.

EPSS

Процентиль: 21%
0.00068
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
5 месяцев назад

A Reflected Cross-site Scripting (XSS) vulnerability exists in the themeSet.php file of ProjectsAndPrograms School Management System 1.0. The application fails to sanitize user-supplied input in the theme POST parameter, allowing an attacker to inject and execute arbitrary JavaScript in a victim's browser.

EPSS

Процентиль: 21%
0.00068
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79