A vulnerability was found in ZeroWdd studentmanager 1.0. It has been rated as problematic. This issue affects the function submitAddPermission of the file src/main/java/com/zero/system/controller/PermissionController. java. The manipulation of the argument url leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
References
| Link | Resource |
|---|---|
| https://github.com/ZeroWdd/manager-system/issues/7 | Not Applicable |
| https://vuldb.com/?ctiid.290231 | Permissions Required VDB Entry |
| https://vuldb.com/?id.290231 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.469217 | Third Party Advisory VDB Entry |
Configurations
History
10 Oct 2025, 17:40
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/ZeroWdd/manager-system/issues/7 - Not Applicable | |
| References | () https://vuldb.com/?ctiid.290231 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.290231 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.469217 - Third Party Advisory, VDB Entry | |
| CPE | cpe:2.3:a:zerowdd:studentmanager:1.0:*:*:*:*:*:*:* | |
| First Time |
Zerowdd
Zerowdd studentmanager |
|
| Summary |
|
06 Jan 2025, 00:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-01-06 00:15
Updated : 2025-10-10 17:40
NVD link : CVE-2024-13143
Mitre link : CVE-2024-13143
CVE.ORG link : CVE-2024-13143
JSON object : View
Products Affected
zerowdd
- studentmanager
