Web / CMS

Cross-Site Scripting (XSS)

CloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS)

CloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS).

5.4
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS58
PUBLISHED
2023-01-16
CVE IDs
CVE-2022-46087
VENDORS
hrshadhin
PUBLIC EXPLOIT
PoC public
CWE
CWE-79
PRODUCT
CloudSchool v3.0.1
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

CloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin users through notification received by the admin user.

CloudSchool v3.0.1 in GitHub repo hrshadhin/school-management-system This vulnerability causes the attacker to execute XSS payloads in the session of another user which may result to cookie stealing or executing malicious scripts in the victim’s browser.

Attack scenario:

In this scenario there are two users where the user “superadmin” has all the permission to the application also the victim in this scenario and the user “admin1”, the attacker in this scenario has only the permission to Create,Edit,Delete Employees and users.

The vulnerability causes the use of a payload “<script>alert(141)</script>” by the user “admin1” to create an employee with the name as the payload. After creating the employee, a notification is raised when we login to the app as the “superadmin” user. Due to the lack of sanitization of the input the Javascript payload gets executed in the session of the “superadmin” user. This behavior can be replicated in any scenarios where the victim user receives a notification.

Vulnerability details

Vulnerability details

CVE-2022-46087
CWE-79
Medium | 5.4

CloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin users through notification received by the admin user.

Auth:
Any authenticated user (remote, user interaction required)
Impact:
Limited data disclosure, limited data tampering; impact extends beyond the vulnerable component
DISCLOSURE

Disclosure timeline

2022-11-25 Reported On

2022-11-22 Made Public On

Fixed On: Not Fixed

Credits

Soummya Mukhopadhyay