6.1
CVSSv3

CVE-2019-14696

Published: 06/08/2019 Updated: 13/08/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

open-school open-school 3.0

open-school open-school 2.3

Exploits

# Exploit Title: [title] # Date: [2019 08 06] # Exploit Author: [GregPriest] # Vendor Homepage: [open-schoolorg/] # Software Link: [] # Version: [Open-School 30/Community Edition 23] # Tested on: [Windows/Linux ] # CVE : [CVE-2019-14696] Open-School 30, and Community Edition 23, allows XSS via the /indexphp?r=students/guardians/cre ...
Open-School version 30 and Community Edition 23 suffers from a cross site scripting vulnerability ...