Back to Database
Status published
High
CVE-2024-28097
Stored Cross-site Scripting in Calendar functionality in Schoolbox
Vulnerability Description
Calendar functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting allowing authenticated attacker to perform security actions in the context of the affected users.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-28097
Credits & Attribution
No credits recorded in the NVD database.
References
More from Schoolbox Pty Ltd
View All →CVE-2024-28096
Stored Cross-site Scripting in Class functionality in Schoolbox
High
7.3
CVE-2024-28095
Stored Cross-site Scripting in News functionality in Schoolbox
High
7.3
CVE-2024-28094
Blind SQL Injection in Chat functionality in Schoolbox
High
8.8
CVE-2022-3059
SQL injection in Schoolbox version 21.0.2, by Schoolbox Pty Ltd
High
8.6
CVE-2022-39020
Cross-site scripting in Schoolbox version 21.0.2, by Schoolbox Pty Ltd
High
7.6
Affected Vendor
Schoolbox Pty Ltd
View all reports →Affected Software
Schoolbox
Vulnerable Versions:
0
Timeline
Official Publish:
March 7th, 2024
Last Modified:
August 26th, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N