Security Advisory

CVE-2024-28277

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-05-13 19:51:05
Last updated 2025-03-27 19:51:30
Assigner mitre
State PUBLISHED

Description

In Sourcecodester School Task Manager v1.0, a vulnerability was identified within the subject_name= parameter, enabling Stored Cross-Site Scripting (XSS) attacks. This vulnerability allows attackers to manipulate the subjects name, potentially leading to the execution of malicious JavaScript payloads.