PT-2022-10231 · Unknown · Student Management System

CVE-2021-33371

·

Published

2022-07-27

·

Updated

2025-04-22

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Student Management System version 1.0
Description A stored cross-site scripting (XSS) issue in the "/nav bar action.php" API endpoint allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Chat box. This enables the execution of malicious code on the client-side.
Recommendations For Student Management System version 1.0, consider disabling the /nav bar action.php endpoint or restricting access to it until a proper fix is applied, and ensure proper input validation and sanitization for the Chat box to prevent malicious payload injection.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-33371

Affected Products

Student Management System