CVE-2024-34240

QDOCS Smart School 7.0.0 is vulnerable to Cross Site Scripting (XSS) resulting in arbitrary code execution in admin functions related to adding or updating records.
Configurations

No configuration.

History

21 Nov 2024, 09:18

Type Values Removed Values Added
References () https://grumpz.net/cve-2024-34240-latest-stored-xss-0day-vulnerability-unveiled - () https://grumpz.net/cve-2024-34240-latest-stored-xss-0day-vulnerability-unveiled -

20 Aug 2024, 15:35

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
Summary
  • (es) QDOCS Smart School 7.0.0 es vulnerable a Cross Site Scripting (XSS), lo que resulta en la ejecución de código arbitrario en funciones administrativas relacionadas con la adición o actualización de registros.

21 May 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-21 18:15

Updated : 2024-11-21 09:18


NVD link : CVE-2024-34240

Mitre link : CVE-2024-34240

CVE.ORG link : CVE-2024-34240


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')