Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-92x3-mfjp-j3h3

Опубликовано: 30 нояб. 2025
Источник: github
Github: Прошло ревью
CVSS4: 1.9
CVSS3: 2.4

Описание

yungifez Skuul School Management System vulnerable to XSS via SVG

A weakness has been identified in yungifez Skuul School Management System up to 2.6.5. This vulnerability affects unknown code of the file /dashboard/schools/1/edit of the component SVG File Handler. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

Пакеты

Наименование

yungifez/skuul

composer
Затронутые версииВерсия исправления

<= 2.6.5

Отсутствует

EPSS

Процентиль: 11%
0.00037
Низкий

1.9 Low

CVSS4

2.4 Low

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 2.4
nvd
2 месяца назад

A weakness has been identified in yungifez Skuul School Management System up to 2.6.5. This vulnerability affects unknown code of the file /dashboard/schools/1/edit of the component SVG File Handler. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

EPSS

Процентиль: 11%
0.00037
Низкий

1.9 Low

CVSS4

2.4 Low

CVSS3

Дефекты

CWE-79