CVE-2021-30113

Publication date

2021-04-08 11:12:20

Family

mitre

State

PUBLISHED

Description

A blind XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in event name and description fields. An attacker can inject a JavaScript code that will be stored in the page. If any visitor sees the event, then the payload will be executed and sends the victims information to the attacker website.