VYPR
Vendor

Eskooly

Products
3
CVEs
8
Across products
11
Status
Private

Products

3

Recent CVEs

8
  • CVE-2024-27712CriJul 5, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the User Account Mangemnt component in the authentication mechanism.

  • CVE-2024-27710CriJul 5, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the authentication mechanism.

  • CVE-2024-27709CriJul 5, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Eskooly Web Product v.3.0 allows a remote attacker to execute arbitrary code via the searchby parameter of the allstudents.php component and the id parameter of the requestmanager.php component.

  • CVE-2024-27713HigJul 5, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the HTTP Response Header Settings component.

  • CVE-2024-27711HigJul 5, 2024
    risk 0.57cvss 8.8epss 0.00

    An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the Sin-up process function in the account settings.

  • CVE-2024-27715HigJul 5, 2024
    risk 0.53cvss 8.2epss 0.00

    An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via a crafted request to the Password Change mechanism.

  • CVE-2024-27717MedJul 5, 2024
    risk 0.42cvss 6.5epss 0.00

    Cross Site Request Forgery vulnerability in Eskooly Free Online School Management Software v.3.0 and before allows a remote attacker to escalate privileges via the Token Handling component.

  • CVE-2024-27716MedJul 5, 2024
    risk 0.35cvss 5.4epss 0.00

    Cross Site Scripting vulnerability in Eskooly Web Product v.3.0 and before allows a remote attacker to execute arbitrary code via the message sending and user input fields.