Cross-site Scripting in School ERP Pro+Responsive by AROX SOLUTION
Vulnerability Description
Vulnerability in School ERP Pro+Responsive 1.0 that allows XSS via the index '/schoolerp/office_admin/' in the parameters es_bankacc, es_bank_name, es_bank_pin, es_checkno, es_teller_number, dc1 and dc2. An attacker could send a specially crafted JavaScript payload to an authenticated user and partially hijack their browser session.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-4823
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Rafael Pedrero
Affected Vendor
AROX SOLUTION
View all reports →