Back

HIGH

Cross-Site Scripting (XSS) vulnerability in Janobe products

Published Aug 6, 2024

Description

Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'View' parameter in '/course/index.php'.

Affected products

Remediation

Vendor solution

There is no reported solution at this time.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published Aug 6, 2024
Updated Aug 6, 2024
Reserved Apr 29, 2024
CISA Vulnrichment
Updated Aug 6, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a