Junglewise Threat Intelligence

CVE-2024-47096: Follett School Solutions Destiny XSS in handleloginform.do

CVE-2024-47096 · Severity: info · CVSS 5.1 · Published 2026-05-28

Technologies: Follett School Solutions Destiny Library Manager. Vendors: Follett School Solutions.

Executive brief

Follett Destiny, a widely used library management system for schools, contains a security flaw that could allow an attacker to run malicious code in a user's web browser. By tricking a staff member or student into clicking a specially crafted link, an attacker could potentially steal login session information or perform unauthorized actions on their behalf. This could lead to unauthorized access to school library records or administrative functions.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Follett School Solutions Destiny versions prior to v22.0.1 AU1. The flaw is located in the 'handleloginform.do' endpoint, which fails to properly sanitize the 'showSupportExpiredMessage' parameter before including it in the server's response. A remote, unauthenticated attacker can exploit this by crafting a malicious URL and inducing a victim to visit it. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized data access. The issue is addressed in version v22.0.1 AU1.

Affected products

  • Follett School Solutions Destiny Library Manager before v22.0.1 AU1

Timeline

  • 2026-05-28: disclosed: CVE published and disclosed by Securin

References

Related threats