CVE-2024-28095

XSS in News functionality in Schoolbox

Discovered by Akshay Raj on behalf of The Missing Link Security

Vulnerability Details

News functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting allowing authenticated attacker to perform security actions in the context of the affected users.

Affected Versions

Before 23.1.3

Fixed Versions

Fixed in: 23.1.3

Latest News