Vulnerability Description
A stored XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in the event name and description fields. An attack can inject a JavaScript code that will be stored in the page. If any visitor sees the events, then the payload will be executed.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Web-School | Enterprise Resource Planning | 5.0 |
Related Weaknesses (CWE)
References
- http://web-school.inProduct
- https://github.com/0xrayan/CVEs/issues/4ExploitIssue TrackingThird Party Advisory
- https://web-school.in/try-demo/Product
- http://web-school.inProduct
- https://github.com/0xrayan/CVEs/issues/4ExploitIssue TrackingThird Party Advisory
- https://web-school.in/try-demo/Product
FAQ
What is CVE-2021-30111?
CVE-2021-30111 is a vulnerability with a CVSS score of 5.4 (MEDIUM). A stored XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in the event name and description fields. An attack can inject a JavaScript code that will be stored in the page. If any visi...
How severe is CVE-2021-30111?
CVE-2021-30111 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-30111?
Check the references section above for vendor advisories and patch information. Affected products include: Web-School Enterprise Resource Planning.