Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-14696 PoC — Open-School 跨站脚本漏洞

Source
Associated Vulnerability
Title:Open-School 跨站脚本漏洞 (CVE-2019-14696)
Description:Open-School是一套基于Web的学校管理软件。该软件提供在线收费、考勤和在线图书馆等功能。Open-School Community Edition是Open-School的社区版。 Open-School 3.0版本和Community Edition 2.3版本中存在跨站脚本漏洞。该漏洞源于WEB应用缺少对客户端数据的正确验证。攻击者可利用该漏洞执行客户端代码。
Description
Open-School 3.0, and Community Edition 2.3, allows cross-site scripting via the osv/index.php?r=students/guardians/create id parameter.
File Snapshot

id: CVE-2019-14696 info: name: Open-School 3.0/Community Edition 2.3 - Cross-Site Scripting aut ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.