Vulnerabilities > WEB School
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-04-08 | CVE-2021-30114 | Cross-Site Request Forgery (CSRF) vulnerability in Web-School Enterprise Resource Planning 5.0 Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a voucher payment request through module/accounting/voucher/create. | 6.5 |
2021-04-08 | CVE-2021-30113 | Cross-site Scripting vulnerability in Web-School Enterprise Resource Planning 5.0 A blind XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in event name and description fields. | 6.1 |
2021-04-08 | CVE-2021-30112 | Cross-Site Request Forgery (CSRF) vulnerability in Web-School Enterprise Resource Planning 5.0 Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a student_leave_application request through module/core/studentleaveapplication/create. | 6.5 |
2021-04-08 | CVE-2021-30111 | Cross-site Scripting vulnerability in Web-School Enterprise Resource Planning 5.0 A stored XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in the event name and description fields. | 5.4 |