CVE-2026-4991

A vulnerability was detected in QDOCS Smart School Management System up to 7.2. The impacted element is an unknown function of the file /admin/enquiry of the component Admission Enquiry Module. Performing a manipulation of the argument Note results in cross site scripting. The attack is possible to be carried out remotely.
Configurations

No configuration.

History

24 Apr 2026, 16:36

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad fue detectada en QDOCS Smart School Management System hasta la versión 7.2. El elemento afectado es una función desconocida del archivo /admin/enquiry del componente Módulo de Consulta de Admisión. Realizar una manipulación del argumento Note resulta en cross-site scripting. El ataque es posible de llevar a cabo de forma remota.

27 Mar 2026, 23:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-27 23:17

Updated : 2026-04-24 16:36


NVD link : CVE-2026-4991

Mitre link : CVE-2026-4991

CVE.ORG link : CVE-2026-4991


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')