CVE-2025-50584 Details
Description
StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Teacher module.
A cross-site scripting (XSS) vulnerability has been identified in StudentManage version 1.0, specifically within the 'Add A New Teacher' module. This issue allows for the injection of malicious scripts that could be executed in the context of the user's browser.
It is recommended to implement input validation and sanitization to check user inputs for harmful scripts before processing or displaying them.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/SimonKang949/Vulnerabilities/issues/3 | CISA-ADP | ExploitIssue Tracking |
| https://gitee.com/DayCloud/student-manage | [email protected] | Product |
| https://github.com/SimonKang949/Vulnerabilities/issues/3 | [email protected] | ExploitIssue Tracking |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| daycloud studentmanage | 1.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 9, 2025 | Initial Analysis | [email protected] |
| Jul 21, 2025 | CVE Modified | CISA-ADP |
| Jul 18, 2025 | New CVE Received | [email protected] |