School software flaws enable unauthenticated XSS
Two chainable vulnerabilities in ProjectsAndPrograms school-management software let an unauthenticated attacker inject JavaScript and guess predictable passwords.
CERT Polska coordinated disclosure of two vulnerabilities in the open-source ProjectsAndPrograms school-management-system. CVE-2026-47324 is a stored XSS affecting multiple attributes of student and teacher objects, normally requiring an authenticated user such as a teacher or admin to inject malicious script. However, when chained with a previously disclosed vulnerability, CVE-2025-11661, which exposes backend endpoints without authentication, an unauthenticated remote attacker can achieve the same JavaScript injection and execution against other users' browsers.
A second issue, CVE-2026-47325, stems from weak credential generation: student and teacher passwords are derived solely from the user's date of birth (e.g., 12072000) and the system never forces a password change on first login. This makes credentials trivially guessable, allowing attackers to log in as legitimate users without needing to exploit any technical flaw.
The vendor was notified but did not provide information on affected versions; only the commit 6b6fae5 build was confirmed vulnerable during testing, though other versions may share the same code paths. No active exploitation has been reported; this is a coordinated vulnerability disclosure rather than an observed attack campaign.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/06/CVE-2026-47324
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free