DayCloud
Products
1- 6 CVEs
Recent CVEs
6| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-50585 | Hig | 0.57 | 8.8 | 0.00 | Jul 18, 2025 | StudentManage v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/adminStudentUrl. | ||
| CVE-2025-2351 | Hig | 0.47 | 7.3 | 0.00 | Mar 16, 2025 | A vulnerability classified as critical was found in DayCloud StudentManage 1.0. This vulnerability affects unknown code of the file /admin/adminScoreUrl of the component Login Endpoint. The manipulation of the argument query leads to sql injection. The attack can be initiated… | ||
| CVE-2025-50586 | Med | 0.42 | 6.5 | 0.00 | Jul 18, 2025 | StudentManage v1.0 was discovered to contain Cross-Site Request Forgery (CSRF). | ||
| CVE-2025-50583 | Med | 0.31 | 4.8 | 0.00 | Jul 18, 2025 | StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Student module. | ||
| CVE-2025-50582 | Med | 0.31 | 4.8 | 0.00 | Jul 18, 2025 | StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Course module. | ||
| CVE-2025-50584 | Med | 0.31 | 4.8 | 0.00 | Jul 18, 2025 | StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Teacher module. |
- risk 0.57cvss 8.8epss 0.00
StudentManage v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/adminStudentUrl.
- risk 0.47cvss 7.3epss 0.00
A vulnerability classified as critical was found in DayCloud StudentManage 1.0. This vulnerability affects unknown code of the file /admin/adminScoreUrl of the component Login Endpoint. The manipulation of the argument query leads to sql injection. The attack can be initiated…
- risk 0.42cvss 6.5epss 0.00
StudentManage v1.0 was discovered to contain Cross-Site Request Forgery (CSRF).
- risk 0.31cvss 4.8epss 0.00
StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Student module.
- risk 0.31cvss 4.8epss 0.00
StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Course module.
- risk 0.31cvss 4.8epss 0.00
StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Teacher module.