🔙 목록으로 돌아가기

CVE-2019-14696: Open-School 3.0/Community Edition 2.3 - Cross-Site Scripting

TitleOpen-School 3.0/Community Edition 2.3 - Cross-Site Scripting
Authorpikpikcu
SeverityMedium
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.
RemediationTo remediate this issue, it is recommended to implement proper input validation and sanitization techniques to prevent the execution of malicious scripts.
CVSS Score6.1
EPSS Score0.13448
CVE IDCVE-2019-14696
CWE IDCWE-79
Tags cve cve2019 xss open-school packetstorm vuln

🔍 Vulnerability Description

Open-School 3.0, and Community Edition 2.3, allows cross-site scripting via the osv/index.php?r=students/guardians/create id parameter.

🌐 HTTP Request

No request captured.

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-14696.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-14696.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A