{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-13784","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2025-11-29T12:59:34.961Z","datePublished":"2025-11-30T07:02:05.901Z","dateUpdated":"2025-12-03T15:30:37.589Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2025-11-30T07:02:05.901Z"},"title":"yungifez Skuul School Management System SVG File edit cross site scripting","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-79","lang":"en","description":"Cross Site Scripting"}]},{"descriptions":[{"type":"CWE","cweId":"CWE-94","lang":"en","description":"Code Injection"}]}],"affected":[{"vendor":"yungifez","product":"Skuul School Management System","versions":[{"version":"2.6.0","status":"affected"},{"version":"2.6.1","status":"affected"},{"version":"2.6.2","status":"affected"},{"version":"2.6.3","status":"affected"},{"version":"2.6.4","status":"affected"},{"version":"2.6.5","status":"affected"}],"modules":["SVG File Handler"]}],"descriptions":[{"lang":"en","value":"A weakness has been identified in yungifez Skuul School Management System up to 2.6.5. This vulnerability affects unknown code of the file /dashboard/schools/1/edit of the component SVG File Handler. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":4.8,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":2.4,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R","baseSeverity":"LOW"}},{"cvssV3_0":{"version":"3.0","baseScore":2.4,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R","baseSeverity":"LOW"}},{"cvssV2_0":{"version":"2.0","baseScore":3.3,"vectorString":"AV:N/AC:L/Au:M/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"}}],"timeline":[{"time":"2025-11-29T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2025-11-29T01:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2025-11-29T14:04:49.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"Zeeshan Khan (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/?id.333788","name":"VDB-333788 | yungifez Skuul School Management System SVG File edit cross site scripting","tags":["vdb-entry"]},{"url":"https://vuldb.com/?ctiid.333788","name":"VDB-333788 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.689012","name":"Submit #689012 | yungifez Skuul v2.6.5 Open Redirect","tags":["third-party-advisory"]},{"url":"https://gist.github.com/thezeekhan/7fc54fd44bc5f318be0350b367b2d8ff","tags":["exploit"]}]},"adp":[{"references":[{"url":"https://vuldb.com/?submit.689012","tags":["exploit"]},{"url":"https://gist.github.com/thezeekhan/7fc54fd44bc5f318be0350b367b2d8ff","tags":["exploit"]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-12-03T15:30:33.805536Z","id":"CVE-2025-13784","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-12-03T15:30:37.589Z"}}]}}