VulnerabilityModified
CVE-2021-29055
Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Firtstname parameter to the Update Account form in student_profile.php.
MEDIUM 6.1EPSS 0.90%
Does this matter?
Lower severity and a low EPSS score (0.90%). Track it; it rarely justifies an emergency change on its own.
Description
Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Firtstname parameter to the Update Account form in student_profile.php.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.90% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- school file management system project/school file management system
- Source
- cve@mitre.org
References
- https://packetstormsecurity.com/files/161394/School-File-Management-System-1.0-Cross-Site-Scripting.htmlThird Party Advisory, VDB Entry
- https://www.sourcecodester.com/php/14155/school-file-management-system.htmlExploit, Third Party Advisory
- https://packetstormsecurity.com/files/161394/School-File-Management-System-1.0-Cross-Site-Scripting.htmlThird Party Advisory, VDB Entry
- https://www.sourcecodester.com/php/14155/school-file-management-system.htmlExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.