U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-45057

Change History

New CVE Received by NIST 8/28/2024 5:15:07 PM

Action Type Old Value New Value
Added CVSS V3

								
							
							
						
GitHub, Inc. AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Added CWE

								
							
							
						
GitHub, Inc. CWE-79
Added Description

								
							
							
						
i-Educar is free, completely online school management software that allows school secretaries, teachers, coordinators and area managers. The lack of sanitization of user-controlled parameters for generating HTML field values ​​dynamically leads to XSS (Cross-Site Scripting) attacks. The dynamic generation of HTML fields in the ieducar/intranet/include/clsCampos.inc.php file does not perform the correct validation or sanitization, reflecting the user-controlled values ​​to be shown in the page's HTML. This allows an attacker to inject a specific XSS payload into a parameter. Successful exploitation of this flaw allows an attacker to trick the victim into clicking a vulnerable URL, enabling JavaScript scripts to be executed in the browser. Due to the configuration of session cookies, with the HttpOnly and SameSite=Lax flags being defined, there is little an attacker can do to steal the session or force the victim to perform actions within the application. This issue hast been patched but a new release has not yet been made. Users are advised to contact the developer and to coordinate an update schedule.
Added Reference

								
							
							
						
GitHub, Inc. https://github.com/portabilis/i-educar/commit/f2d768534aabc09b2a1fc8a5cc5f9c93925cb273 [No types assigned]
Added Reference

								
							
							
						
GitHub, Inc. https://github.com/portabilis/i-educar/security/advisories/GHSA-fqwh-c3c8-7gwj [No types assigned]