Web School maintains an enterprise resource planning platform with a narrow product footprint and limited disclosed vulnerability history. Current exposure counts and severity assessments are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Web School over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-30114MEDIUM Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a voucher payment request through module/accounting/voucher/ | Apr 8, 2021 | 6.5 | 21 | NO | NO |
CVE-2021-30113MEDIUM A blind XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in event name and description fields. An attacker can inject a JavaScript code that will be stored in the | Apr 8, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-30112MEDIUM Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a student_leave_application request through module/core/stud | Apr 8, 2021 | 6.5 | 21 | NO | NO |
CVE-2021-30111MEDIUM A stored XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in the event name and description fields. An attack can inject a JavaScript code that will be stored in t | Apr 8, 2021 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Web School.
Media articles that mention a CVE ID that affects a product developed by Web School — matched by CVE ID, not by vendor name.