CVE Published: 08/10/2024 |
CVE Updated: 08/10/2024 |
CVE Year: 2024 Source: securin |
Vendor: Follet School Solutions |
Product: Destiny Status : PUBLISHED
CVE-2024-47095 Description
Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a remote attacker to run arbitrary client-side code via the expiredSupportMessage parameter of handleloginform.do.
CWE-ID: CWE-79 CWE Name: CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or
Cross-site Scripting
) Source: Follet School Solutions
Common Attack Pattern Enumeration and Classification (CAPEC)