CVE-2025-1159

CVSS 3.1 Score 3.5 of 10 (low)

Details

Published Feb 10, 2025
Updated: Feb 11, 2025
CWE ID 94
CWE ID 79

Summary

CVE-2025-1159 is a recently identified vulnerability affecting the CampCodes School Management Software version 1.0. This issue is considered problematic due to the presence of a cross-site scripting (XSS) vulnerability. The flaw is located in an unspecified functionality of the /academic-calendar file. Successful exploitation allows attackers to inject malicious scripts into a user's browser, potentially leading to data theft or unauthorized actions. The vulnerability can be exploited remotely, increasing the risk to organizations using the software. The exploit details have been made public, increasing the threat level for victims who have not yet applied a patch.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share