Vulnerabilities > WEB School

DATE CVE VULNERABILITY TITLE RISK
2021-04-08 CVE-2021-30114 Cross-Site Request Forgery (CSRF) vulnerability in Web-School Enterprise Resource Planning 5.0
Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a voucher payment request through module/accounting/voucher/create.
network
low complexity
web-school CWE-352
6.5
2021-04-08 CVE-2021-30113 Cross-site Scripting vulnerability in Web-School Enterprise Resource Planning 5.0
A blind XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in event name and description fields.
network
low complexity
web-school CWE-79
6.1
2021-04-08 CVE-2021-30112 Cross-Site Request Forgery (CSRF) vulnerability in Web-School Enterprise Resource Planning 5.0
Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a student_leave_application request through module/core/studentleaveapplication/create.
network
low complexity
web-school CWE-352
6.5
2021-04-08 CVE-2021-30111 Cross-site Scripting vulnerability in Web-School Enterprise Resource Planning 5.0
A stored XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in the event name and description fields.
network
low complexity
web-school CWE-79
5.4