A stored XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in the event name and description fields. An attack can inject a JavaScript code that will be stored in the page. If any visitor sees the events, then the payload will be executed.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://web-school.in/try-demo/ | product |
http://web-school.in | product |
https://github.com/0xrayan/CVEs/issues/4 | issue tracking exploit third party advisory |