Back

HIGH

Cross-Site Scripting (XSS) vulnerability in Janobe School Event Management System

Published Aug 6, 2024

Description

Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session details via the 'view' parameter in /candidate/index.php'.

Affected products

Remediation

Vendor solution

There is no reported solution at this time.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner INCIBE
Published Aug 6, 2024
Updated Aug 8, 2024
Reserved Apr 29, 2024

CISA Vulnrichment

Updated Aug 8, 2024

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner INCIBE
Published Aug 6, 2024
Updated Aug 8, 2024

GitHub

No data