VulnerabilityAnalyzed
CVE-2024-22936
Cross-site scripting (XSS) vulnerability in Parents & Student Portal in Genesis School Management Systems in Genesis AIMS Student Information Systems v.3053 allows remote attackers to inject arbitrary web script or HTML via the message parameter.
MEDIUM 6.1EPSS 0.56%
Does this matter?
Lower severity and a low EPSS score (0.56%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in Parents & Student Portal in Genesis School Management Systems in Genesis AIMS Student Information Systems v.3053 allows remote attackers to inject arbitrary web script or HTML via the message parameter.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.56% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- manuelaldape/parents \& student portal
- Source
- cve@mitre.org
References
- https://github.com/SnoopJesus420/CVEs/blob/main/CVE-2023-Broken Link
- https://github.com/SnoopJesus420/CVEs/blob/main/CVEs-2024/CVE-2024-22936.mdExploit, Third Party Advisory
- https://github.com/SnoopJesus420/CVEs/blob/main/CVE-2023-Broken Link
- https://github.com/SnoopJesus420/CVEs/blob/main/CVEs-2024/CVE-2024-22936.mdExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.