A weakness has been identified in yungifez Skuul School Management System up to 2.6.5. This vulnerability affects unknown code of the file /dashboard/schools/1/edit of the component SVG File Handler. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
History

Sat, 06 Dec 2025 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Yungifez skuul
CPEs cpe:2.3:a:yungifez:skuul:*:*:*:*:*:*:*:*
Vendors & Products Yungifez skuul

Wed, 03 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 01 Dec 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Yungifez
Yungifez skuul School Management System
Vendors & Products Yungifez
Yungifez skuul School Management System

Sun, 30 Nov 2025 07:15:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in yungifez Skuul School Management System up to 2.6.5. This vulnerability affects unknown code of the file /dashboard/schools/1/edit of the component SVG File Handler. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
Title yungifez Skuul School Management System SVG File edit cross site scripting
Weaknesses CWE-79
CWE-94
References
Metrics cvssV2_0

{'score': 3.3, 'vector': 'AV:N/AC:L/Au:M/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 2.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 2.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-11-30T07:02:05.901Z

Updated: 2025-12-03T15:30:37.589Z

Reserved: 2025-11-29T12:59:34.961Z

Link: CVE-2025-13784

cve-icon Vulnrichment

Updated: 2025-12-03T15:30:26.281Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-30T07:15:44.743

Modified: 2025-12-06T00:26:30.450

Link: CVE-2025-13784

cve-icon Redhat

No data.