A vulnerability, which was classified as problematic, has been found in Campcodes School Management Software 1.0. This issue affects some unknown processing of the file /create-id-card of the component Create Id Card Page. The manipulation of the argument ID Card Title leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
History

Fri, 28 Feb 2025 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Campcodes
Campcodes school Management Software
CPEs cpe:2.3:a:campcodes:school_management_software:1.0:*:*:*:*:*:*:*
Vendors & Products Campcodes
Campcodes school Management Software

Tue, 21 Jan 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 18 Jan 2025 14:15:00 +0000

Type Values Removed Values Added
Description A vulnerability, which was classified as problematic, has been found in Campcodes School Management Software 1.0. This issue affects some unknown processing of the file /create-id-card of the component Create Id Card Page. The manipulation of the argument ID Card Title leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Title Campcodes School Management Software Create Id Card Page create-id-card cross site scripting
Weaknesses CWE-79
CWE-94
References
Metrics cvssV2_0

{'score': 3.3, 'vector': 'AV:N/AC:L/Au:M/C:N/I:P/A:N'}

cvssV3_0

{'score': 2.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 2.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-01-21T21:03:41.680Z

Reserved: 2025-01-17T20:48:50.073Z

Link: CVE-2025-0559

cve-icon Vulnrichment

Updated: 2025-01-21T21:03:05.031Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-18T14:15:25.420

Modified: 2025-02-28T02:02:26.513

Link: CVE-2025-0559

cve-icon Redhat

No data.