Impact
A flaw in the dashboard page of sambitraj STUDENT‑MANAGEMENT‑SYSTEM 1.0 allows an attacker to manipulate the Name parameter so that the value is reflected unescaped in the page output. This reflected input can contain arbitrary script code, enabling cross‑site scripting. The vulnerability can be triggered remotely by sending a crafted HTTP request, and it has been publicly disclosed, meaning attackers can readily use it to run scripts in victims’ browsers, steal session cookies, or perform further malicious actions.
Affected Systems
The affected product is the sambitraj STUDENT‑MANAGEMENT‑SYSTEM, version 1.0. No other versions or variants are listed in the CVE data. The software is available as an open‑source project on GitHub.
Risk and Exploitability
The CVSS score of 4.8 categorizes the vulnerability as moderate. EPSS information is not available, and the issue is not listed in CISA KEV. Because the Name argument can be supplied remotely via an HTTP request, the likely attack vector is remote web exploitation. Since the flaw is publicly known and the vendor has yet to respond, the possibility of exploitation remains, particularly if the endpoint is accessible to unauthenticated users.
OpenCVE Enrichment