VulnerabilityAnalyzed
CVE-2025-0559
A vulnerability, which was classified as problematic, has been found in Campcodes School Management Software 1.0.
MEDIUM 5.1EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability, which was classified as problematic, has been found in Campcodes School Management Software 1.0. This issue affects some unknown processing of the file /create-id-card of the component Create Id Card Page. The manipulation of the argument ID Card Title leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
- CVSS 4.0
- 5.1 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.36% probability · 29th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79, CWE-94
- Affected
- campcodes/school management software
- Source
- cna@vuldb.com
References
- https://github.com/KhukuriRimal/Vulnerabilities/blob/main/CampCodes%20-%20School%20Management%20Software%20-%20Cross%20Site%20Scripting.pdfExploit
- https://vuldb.com/?ctiid.292493Permissions Required, VDB Entry
- https://vuldb.com/?id.292493Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.480306Third Party Advisory, VDB Entry
- https://www.campcodes.com/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.