version 23.1.3 is vulnerable to stored cross-site scripting allowing
authenticated attacker to perform security actions in the context of the
affected users.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-25260 | News functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting allowing authenticated attacker to perform security actions in the context of the affected users. |
Wed, 05 Feb 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Schoolbox
Schoolbox schoolbox |
|
| CPEs | cpe:2.3:a:schoolbox:schoolbox:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Schoolbox
Schoolbox schoolbox |
Status: PUBLISHED
Assigner: TML
Published:
Updated: 2024-08-02T00:48:48.247Z
Reserved: 2024-03-04T04:27:20.021Z
Link: CVE-2024-28095
Updated: 2024-08-02T00:48:48.247Z
Status : Analyzed
Published: 2024-03-07T04:15:07.527
Modified: 2026-06-17T07:20:57.553
Link: CVE-2024-28095
No data.
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
EUVD