ZeroHour

CVE-2021-28424

PoC ×3
CVSS 3.1
5.4 medium
EPSS
1%p69
Published
()
Modified
Description

A stored cross-site scripting (XSS) vulnerability in Teachers Record Management System 1.0 allows remote authenticated users to inject arbitrary web script or HTML via the 'email' POST parameter in adminprofile.php.

Vendors
phpgurukul
Products
teachers record management system
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.