CVE-2019-14696 | Open-school 2.3/3.0 create ID cross site scripting (ID 153984 / EDB-47212)
A vulnerability was found in Open-school 2.3/3.0. It has been declared as problematic. Affected by this issue is some unknown functionality of the file osv/index.php?r=students/guardians/create. Executing manipulation of the argument ID as part of Parameter can lead to cross site scripting.
This vulnerability appears as CVE-2019-14696. The attack may be performed from remote. In addition, an exploit is available.