Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-26068 | A Reflected Cross-site Scripting (XSS) vulnerability exists in the themeSet.php file of ProjectsAndPrograms School Management System 1.0. The application fails to sanitize user-supplied input in the theme POST parameter, allowing an attacker to inject and execute arbitrary JavaScript in a victim's browser. |
Tue, 09 Sep 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oranbyte
Oranbyte school Management System |
|
| CPEs | cpe:2.3:a:oranbyte:school_management_system:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Oranbyte
Oranbyte school Management System |
Thu, 28 Aug 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
School Management System Project
School Management System Project school Management System |
|
| Vendors & Products |
School Management System Project
School Management System Project school Management System |
Thu, 28 Aug 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Thu, 28 Aug 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Reflected Cross-site Scripting (XSS) vulnerability exists in the themeSet.php file of ProjectsAndPrograms School Management System 1.0. The application fails to sanitize user-supplied input in the theme POST parameter, allowing an attacker to inject and execute arbitrary JavaScript in a victim's browser. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-08-28T20:11:01.022Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-51967
Updated: 2025-08-28T20:10:55.146Z
Status : Analyzed
Published: 2025-08-28T14:15:47.800
Modified: 2025-09-09T18:43:07.110
Link: CVE-2025-51967
No data.
OpenCVE Enrichment
Updated: 2025-08-28T21:29:55Z
EUVD