CVE-2022-39020

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
31/10/2022
Last modified:
25/10/2023

Description

<br /> Multiple instances of XSS (stored and reflected) was found in the application. For example, features such as student assessment submission, file upload, news, ePortfolio and calendar event creation were found to be vulnerable to cross-site scripting.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:schoolbox:schoolbox:21.0.2:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools