CVE-2025-1159
CVSS 3.1 Score 3.5 of 10 (low)
Details
Summary
CVE-2025-1159 is a recently identified vulnerability affecting the CampCodes School Management Software version 1.0. This issue is considered problematic due to the presence of a cross-site scripting (XSS) vulnerability. The flaw is located in an unspecified functionality of the /academic-calendar file. Successful exploitation allows attackers to inject malicious scripts into a user's browser, potentially leading to data theft or unauthorized actions. The vulnerability can be exploited remotely, increasing the risk to organizations using the software. The exploit details have been made public, increasing the threat level for victims who have not yet applied a patch.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- CampCodes School Management Software