VYPR

NewSiteServer

by CyberTutor

CVEs (2)

  • CVE-2026-19852MedAug 24, 2026
    risk 0.40cvss 6.1epss

    NewSiteServer (NSS) developed by CyberTutor has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload arbitrary files, including malicious HTML files, thereby achieving effects similar to cross-site scripting.

  • CVE-2026-19853MedAug 24, 2026
    risk 0.34cvss 5.3epss

    NewSiteServer (NSS) developed by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers can exploit a specific functionality to send emails to anyone on behalf of the school.