Description
Vulnerability in School ERP Pro+Responsive 1.0 that allows XSS via the index '/schoolerp/office_admin/' in the parameters es_bankacc, es_bank_name, es_bank_pin, es_checkno, es_teller_number, dc1 and dc2. An attacker could send a specially crafted JavaScript payload to an authenticated user and partially hijack their browser session.
No analysis available yet.
Remediation
Vendor Solution
There is no reported solution at this time.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-44414 | Vulnerability in School ERP Pro+Responsive 1.0 that allows XSS via the index '/schoolerp/office_admin/' in the parameters es_bankacc, es_bank_name, es_bank_pin, es_checkno, es_teller_number, dc1 and dc2. An attacker could send a specially crafted JavaScript payload to an authenticated user and partially hijack their browser session. |
References
History
Thu, 23 Oct 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arox
Arox school Erp Pro\+responsive |
|
| CPEs | cpe:2.3:a:arox:school_erp_pro\+responsive:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Arox
Arox school Erp Pro\+responsive |
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-01T20:55:10.025Z
Reserved: 2024-05-13T07:19:20.469Z
Link: CVE-2024-4823
Updated: 2024-08-01T20:55:10.025Z
Status : Analyzed
Published: 2024-05-14T15:45:14.797
Modified: 2025-10-23T12:27:00.927
Link: CVE-2024-4823
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD