First published: Thu Mar 07 2024(Updated: )
Class functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting allowing authenticated attacker to perform security actions in the context of the affected users.
Credit: vdp@themissinglink.com.au
Affected Software | Affected Version | How to fix |
---|---|---|
Schoolbox | <23.1.3 | |
Schoolbox | <23.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28096 is considered a high-severity vulnerability due to the potential for stored cross-site scripting attacks.
To fix CVE-2024-28096, users should upgrade their Schoolbox application to version 23.1.3 or later.
CVE-2024-28096 affects all versions of the Schoolbox application prior to 23.1.3.
CVE-2024-28096 is a stored cross-site scripting vulnerability.
Yes, an authenticated attacker can exploit CVE-2024-28096 to perform actions in the context of affected users.