PoC Index

CVE-2021-28424

MEDIUM 5.4EPSS 1.3%

A stored cross-site scripting (XSS) vulnerability in Teachers Record Management System 1.0 allows remote authenticated users to inject arbitrary web script or HTML via the 'email' POST parameter in adminprofile.php.

CVSS v3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
EPSS
1.31% chance of exploitation in the next 30 days, 69th percentile
Published
2021-07-01
Updated
2024-08-03

Proof-of-concept exploits (3)

References

Related