web-school records
4 published records for vendor web-school.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
26Monitor | CVE-2021-30112No exploit | Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a student_leave_applweb-school · enterprise resource planning · CWE-352 | Medium6.5 | — | 0.7% | Apr 8, 2021 |
26Monitor | CVE-2021-30114No exploit | Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a voucher payment reweb-school · enterprise resource planning · CWE-352 | Medium6.5 | — | 0.7% | Apr 8, 2021 |
24Monitor | CVE-2021-30113No exploit | A blind XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in event name and description fields.web-school · enterprise resource planning · CWE-79 | Medium6.1 | — | 0.9% | Apr 8, 2021 |
21Monitor | CVE-2021-30111No exploit | A stored XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in the event name and description fields.web-school · enterprise resource planning · CWE-79 | Medium5.4 | — | 0.7% | Apr 8, 2021 |
- CVE-2021-3011226Monitor
Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a student_leave_appl
MediumCVSS 6.5No exploitEPSS 1%web-school · enterprise resource planningApr 8, 2021
- CVE-2021-3011426Monitor
Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a voucher payment re
MediumCVSS 6.5No exploitEPSS 1%web-school · enterprise resource planningApr 8, 2021
- CVE-2021-3011324Monitor
A blind XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in event name and description fields.
MediumCVSS 6.1No exploitEPSS 1%web-school · enterprise resource planningApr 8, 2021
- CVE-2021-3011121Monitor
A stored XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in the event name and description fields.
MediumCVSS 5.4No exploitEPSS 1%web-school · enterprise resource planningApr 8, 2021