Security Advisory

CVE-2021-30113

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-04-08 11:12:20
Last updated 2024-08-03 22:24:59
Assigner mitre
State PUBLISHED

Description

A blind XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in event name and description fields. An attacker can inject a JavaScript code that will be stored in the page. If any visitor sees the event, then the payload will be executed and sends the victims information to the attacker website.