First published: Thu Mar 07 2024(Updated: )
News functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting allowing authenticated attacker to perform security actions in the context of the affected users.
Credit: vdp@themissinglink.com.au
Affected Software | Affected Version | How to fix |
---|---|---|
Schoolbox | <23.1.3 | |
Schoolbox | <23.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28095 is classified as a high severity vulnerability due to its potential for stored cross-site scripting.
To fix CVE-2024-28095, upgrade the Schoolbox application to version 23.1.3 or later.
CVE-2024-28095 affects all users of the Schoolbox application prior to version 23.1.3.
CVE-2024-28095 can facilitate stored cross-site scripting attacks, allowing an authenticated attacker to execute scripts in the context of affected users.
Schoolbox versions before 23.1.3 are vulnerable to CVE-2024-28095.