A vulnerability was found in ZeroWdd studentmanager 1.0. It has been rated as problematic. This issue affects the function submitAddPermission of the file src/main/java/com/zero/system/controller/PermissionController. java. The manipulation of the argument url leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/ZeroWdd/manager-system/issues/7 | Not Applicable | 
| https://vuldb.com/?ctiid.290231 | Permissions Required VDB Entry | 
| https://vuldb.com/?id.290231 | Third Party Advisory VDB Entry | 
| https://vuldb.com/?submit.469217 | Third Party Advisory VDB Entry | 
Configurations
                    History
                    10 Oct 2025, 17:40
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:zerowdd:studentmanager:1.0:*:*:*:*:*:*:* | |
| Summary | 
 | |
| First Time | Zerowdd studentmanager Zerowdd | |
| References | () https://github.com/ZeroWdd/manager-system/issues/7 - Not Applicable | |
| References | () https://vuldb.com/?ctiid.290231 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.290231 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.469217 - Third Party Advisory, VDB Entry | 
06 Jan 2025, 00:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-01-06 00:15
Updated : 2025-10-10 17:40
NVD link : CVE-2024-13143
Mitre link : CVE-2024-13143
CVE.ORG link : CVE-2024-13143
JSON object : View
Products Affected
                zerowdd
- studentmanager
