Junglewise Threat Intelligence

CVE-2024-47097: Follett School Solutions Destiny XSS in handleloginform.do

CVE-2024-47097 · Severity: info · CVSS 5.1 · Published 2026-05-28

Technologies: Follett School Solutions Destiny Library Manager. Vendors: Follett School Solutions.

Executive brief

Follett Destiny, a widely used library management system for schools, contains a security flaw that could allow an attacker to execute malicious code in a user's web browser. By tricking a staff member or student into clicking a specially crafted link, an attacker could potentially steal login session information or perform unauthorized actions on their behalf. This could lead to unauthorized access to library records or student data.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Follett School Solutions Destiny versions prior to v22.0.1 AU1. The flaw is located within the 'site' parameter of the 'handleloginform.do' endpoint, which fails to properly neutralize user-supplied input before rendering it in the web page. A remote, unauthenticated attacker can exploit this by crafting a malicious URL and inducing a victim to visit it. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized data access. The issue is addressed in version v22.0.1 AU1.

Affected products

  • Follett School Solutions Destiny Library Manager Before v22.0.1 AU1

Timeline

  • 2026-05-28: disclosed: Initial public disclosure of the vulnerability.
  • 2026-05-28: advisory: NVD record published.

References

Related threats