Junglewise Threat Intelligence

CVE-2025-50582: DayCloud StudentManage XSS in Add A New Course module

CVE-2025-50582 · Severity: medium · CVSS 4.8 · Published 2025-07-18

Technologies: Daycloud Studentmanage. Vendors: Daycloud.

Executive brief

StudentManage, a web-based application for managing student records and course information, contains a security flaw in its course management module. An attacker with administrative access can inject malicious scripts into course names, which then execute in the browsers of other users viewing that data. This could lead to unauthorized actions being performed in the context of another user's session or the theft of sensitive session information.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in StudentManage v1.0 due to improper neutralization of user-supplied input in the 'Add A New Course' module. Specifically, the application fails to sanitize the 'course name' field before storing it in the database and subsequently rendering it in the web interface (CWE-79). An attacker with high privileges (administrator) can submit a payload such as a JavaScript alert script. When another user (such as a student or another admin) views the course management or listing pages, the malicious script executes in their browser. This can be used to hijack sessions or perform unauthorized actions. The vulnerability was identified in the Java/JSP-based implementation hosted on Gitee.

Affected products

  • DayCloud (小楼夜听雨) StudentManage 1.0

Timeline

  • 2025-07-18: disclosed: Vulnerability reported via GitHub issue and assigned CVE-2025-50582.
  • 2025-07-18: advisory

References

Related threats