VYPR

Web Product

by Eskooly

CVEs (5)

  • CVE-2024-27712CriJul 5, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the User Account Mangemnt component in the authentication mechanism.

  • CVE-2024-27709CriJul 5, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Eskooly Web Product v.3.0 allows a remote attacker to execute arbitrary code via the searchby parameter of the allstudents.php component and the id parameter of the requestmanager.php component.

  • CVE-2024-27711HigJul 5, 2024
    risk 0.57cvss 8.8epss 0.00

    An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the Sin-up process function in the account settings.

  • CVE-2024-27715HigJul 5, 2024
    risk 0.53cvss 8.2epss 0.00

    An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via a crafted request to the Password Change mechanism.

  • CVE-2024-27716MedJul 5, 2024
    risk 0.35cvss 5.4epss 0.00

    Cross Site Scripting vulnerability in Eskooly Web Product v.3.0 and before allows a remote attacker to execute arbitrary code via the message sending and user input fields.