In Sourcecodester School Task Manager v1.0, a vulnerability was identified within the subject_name= parameter, enabling Stored Cross-Site Scripting (XSS) attacks. This vulnerability allows attackers to manipulate the subject's name, potentially leading to the execution of malicious JavaScript payloads.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 11 Feb 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Remyandrade
Remyandrade school Task Manager |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:remyandrade:school_task_manager:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Remyandrade
Remyandrade school Task Manager |
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-27T19:51:30.129Z
Reserved: 2024-03-08T00:00:00.000Z
Link: CVE-2024-28277
Updated: 2024-08-02T00:48:49.669Z
Status : Modified
Published: 2024-05-14T15:14:18.617
Modified: 2025-03-27T20:15:24.940
Link: CVE-2024-28277
No data.
OpenCVE Enrichment
No data.
Weaknesses