Today > vulnerabilities   -   You can now download lists of IOCs here!

CVE-2024-28277

May 14, 2024, 4:13 p.m.

Product(s) Impacted

Sourcecodester School Task Manager

  • 1.0

Description

In Sourcecodester School Task Manager v1.0, a vulnerability was identified within the subject_name= parameter, enabling Stored Cross-Site Scripting (XSS) attacks. This vulnerability allows attackers to manipulate the subject's name, potentially leading to the execution of malicious JavaScript payloads.

Weaknesses

Date

Published: May 14, 2024, 3:14 p.m.

Last Modified: May 14, 2024, 4:13 p.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

cve@mitre.org

References