First published: Thu Mar 07 2024(Updated: )
Calendar functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting allowing authenticated attacker to perform security actions in the context of the affected users.
Credit: vdp@themissinglink.com.au
Affected Software | Affected Version | How to fix |
---|---|---|
Schoolbox | <23.1.3 | |
Schoolbox | <23.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28097 has a high severity rating due to its potential for stored cross-site scripting vulnerabilities affecting authenticated users.
To fix CVE-2024-28097, upgrade the Schoolbox application to version 23.1.3 or later.
CVE-2024-28097 affects users of Schoolbox applications prior to version 23.1.3.
CVE-2024-28097 allows an authenticated attacker to perform security actions in the context of affected users via stored cross-site scripting.
CVE-2024-28097 is an active threat for installations of Schoolbox below version 23.1.3.