Cross Site Request Forgery vulnerability in Eskooly Free Online School Management Software v.3.0 and before allows a remote attacker to escalate privileges via the Token Handling component.
                
            References
                    Configurations
                    History
                    28 Apr 2025, 14:47
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://blog.be-hacktive.com/eskooly-cve/cve-2024-27717-cross-site-request-forgery-csrf-in-eskooly-web-product-less-than-v3.0 - Broken Link | |
| CPE | cpe:2.3:a:eskooly:eskooly:*:*:*:*:-:-:*:* | |
| First Time | Eskooly eskooly Eskooly | 
Information
                Published : 2024-07-05 17:15
Updated : 2025-04-28 14:47
NVD link : CVE-2024-27717
Mitre link : CVE-2024-27717
CVE.ORG link : CVE-2024-27717
JSON object : View
Products Affected
                eskooly
- eskooly
CWE
                
                    
                        
                        CWE-352
                        
            Cross-Site Request Forgery (CSRF)
