CVE-2025-41107EPSS p8.3%
CVE-2025-41107CVE-2025-41107
qdocs / smart_school
Description
Stored Cross Site Scripting (XSS) vulnerability in Smart School 7.0 due to lack of proper validation of user input when sending a POST request to '/online_admission', wich affects the parameters 'firstname', 'lastname', 'guardian_name' and others. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal his/her session cookie details.
Scoring
| CVSS | 5.4 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 0.19% probability of exploitation · percentile 8.3% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-07 |