Impact
This vulnerability allows arbitrary JavaScript to be injected into the web application through the dashboard/studentConductManager.php page. The defect is an instance of Cross‑Site Scripting (CWE‑79) and is accompanied by code injection (CWE‑94) weaknesses. Because the vulnerable code can be executed on the client side, an attacker could steal session credentials, deface user interfaces, or manipulate sensitive data. The description specifies that the attack can be performed from remote and that the exploit is publicly disclosed; no server‑side logic is required to trigger the flaw beyond sending a crafted request.
Affected Systems
Wizgrade, the student performance management system provided by Igweze, is affected. All releases that include the repository commit b1d55f22b90cd7e7a6e5002f006d7c649e8086d6 contain the vulnerable code. The product uses a rolling‑release system, so explicit version numbers are not disclosed; administrators should therefore assume that any current or upcoming releases remain at risk until an official fix is published.
Risk and Exploitability
The CVSS score of 5.3 classifies this as a medium‑severity issue. The EPSS score of less than 1% indicates a very low but nonzero probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Because the attack vector is remote and publicly disclosed, a remote attacker could exploit it without requiring privileged access to the system.
OpenCVE Enrichment