The School Club Application System Project maintains a web-based application for managing student club registrations and activities, with its durable vulnerability signal centered on application-layer input handling, particularly cross-site scripting, resource injection, and broader injection-class weaknesses. Treat this as a compact vendor profile reflecting a focused deployment scope; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by School Club Application System Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-1287CRITICAL A vulnerability classified as critical was found in School Club Application System 1.0. This vulnerability affects a request to the file /scas/classes/Users.php?f=save_user. The ma | Apr 9, 2022 | 9.8 | 24 | NO | NO |
CVE-2022-29359MEDIUM A stored cross-site scripting (XSS) vulnerability in /scas/?page=clubs/application_form&id=7 of School Club Application System v0.1 allows attackers to execute arbitrary web script | May 25, 2022 | 6.1 | 17 | NO | NO |
CVE-2022-1288MEDIUM A vulnerability, which was classified as problematic, has been found in School Club Application System 1.0. This issue affects access to /scas/admin/. The manipulation of the param | Apr 9, 2022 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by School Club Application System Project.
Media articles that mention a CVE ID that affects a product developed by School Club Application System Project — matched by CVE ID, not by vendor name.