Junglewise Threat Intelligence

CVE-2026-47324: ProjectsAndPrograms school-management-system Stored XSS in student and teacher objects

CVE-2026-47324 · Severity: info · CVSS 5.1 · Published 2026-06-03

Technologies: ProjectsAndPrograms School Management System.

Executive brief

The ProjectsAndPrograms school-management-system, used for managing educational records, contains a security flaw that allows users to inject malicious scripts into student and teacher profiles. If exploited, an attacker could steal login sessions or perform unauthorized actions when other staff or students view the affected profiles. While normally requiring an account to exploit, this can be combined with other known flaws to allow completely unauthorized attackers to compromise the system.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the ProjectsAndPrograms school-management-system due to improper neutralization of input during web page generation (CWE-79). The flaw resides in multiple attributes of student and teacher objects, allowing an authenticated attacker with teacher or administrator privileges to inject malicious payloads. Notably, this vulnerability can be chained with CVE-2025-11661 (unauthenticated backend access) to allow remote, unauthenticated attackers to inject scripts. The vulnerability was confirmed in the version corresponding to commit 6b6fae5.

Affected products

  • ProjectsAndPrograms school-management-system commit 6b6fae5 and potentially others

Timeline

  • 2026-06-03: advisory: Advisory published by CERT.PL and NVD
  • 2026-06-03: disclosed

References