6.1
CVSSv3

CVE-2022-32118

Published: 15/07/2022 Updated: 22/07/2022
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Arox School ERP Pro v1.0 exists to contain a cross-site scripting (XSS) vulnerability via the dispatchcategory parameter in backoffice.inc.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

arox school erp pro 1.0

Github Repositories

CVE-2022-32118 - Arox-XSS

CVE-2022-32118 - Arox-XSS Stored and Reflected Cross Site Scripting vulnerabilities exist in multiple pages of the Arox School ERP Pro application, including the login page, that allows for arbitrary execution of JavaScript commands The application has many more parameters affected by Cross Site Scripting but listed below are a sample size Stored XSS Vulnerable Pages: localho