Stored XSS in Smart School
Vulnerability Description
Stored Cross Site Scripting (XSS) vulnerability in Smart School 7.0 due to lack of proper validation of user input when sending a POST request to '/online_admission', wich affects the parameters 'firstname', 'lastname', 'guardian_name' and others. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal his/her session cookie details.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-41107
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Gonzalo Aguilar García (6h4ack)
Affected Vendor
QDOCS
View all reports →