VulnerabilityModified
CVE-2021-46824
Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Lastname parameter to the Update Account form in student_profile.php.
MEDIUM 5.4EPSS 0.92%
Does this matter?
Lower severity and a low EPSS score (0.92%). Track it; it rarely justifies an emergency change on its own.
Description
Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Lastname parameter to the Update Account form in student_profile.php.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.92% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- school file management system project/school file management system
- Source
- cve@mitre.org
References
- https://packetstormsecurity.com/files/161394/School-File-Management-System-1.0-Cross-Site-Scripting.htmlThird Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/49559Third Party Advisory, VDB Entry
- https://www.sourcecodester.com/php/14155/school-file-management-system.htmlProduct
- https://packetstormsecurity.com/files/161394/School-File-Management-System-1.0-Cross-Site-Scripting.htmlThird Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/49559Third Party Advisory, VDB Entry
- https://www.sourcecodester.com/php/14155/school-file-management-system.htmlProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.