CVE-2024-13142
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Summary
CVE-2024-13142 is a newly identified vulnerability affecting ZeroWdd studentmanager 1.0. This issue, located in the RoleController.java file, permits cross-site scripting (XSS) attacks. Specifically, the function submitAddRole can be exploited by manipulating the name argument. Since this vulnerability can be triggered remotely, it poses a significant security risk. Attackers can inject malicious scripts, potentially stealing sensitive user data or gaining unauthorized access. Institutions using ZeroWdd studentmanager 1.0 are urged to apply patches or updates immediately to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Zerowdd Studentmanager