Vulnerability Description
phpscriptsmall.com School College Portal with ERP Script 2.6.1 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attack administrators and teachers, students and more. The component is: /pro-school/index.php?student/message/send_reply/. The attack vector is: <img src=x onerror=alert(document.domain) />.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| School College Portal With Erp Script Project | School College Portal With Erp Script | <= 2.6.1 |
Related Weaknesses (CWE)
References
- https://whitehatck01.blogspot.com/2018/02/school-college-portal-with-erp-script.ExploitThird Party Advisory
- https://whitehatck01.blogspot.com/2018/02/school-college-portal-with-erp-script.ExploitThird Party Advisory
FAQ
What is CVE-2019-1010028?
CVE-2019-1010028 is a vulnerability with a CVSS score of 6.1 (MEDIUM). phpscriptsmall.com School College Portal with ERP Script 2.6.1 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attack administrators and teachers, students and more. The compone...
How severe is CVE-2019-1010028?
CVE-2019-1010028 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-1010028?
Check the references section above for vendor advisories and patch information. Affected products include: School College Portal With Erp Script Project School College Portal With Erp Script.