VORANT. Threat Intelligence Sign in Get the full feed

XSS and weak passwords chain in ProjectsAndPrograms

medium vulnerability education

Two vulnerabilities in the ProjectsAndPrograms school-management-system can be chained for unauthenticated stored XSS and account takeover via predictable passwords.

CERT Polska coordinated disclosure of two vulnerabilities affecting the ProjectsAndPrograms school-management-system, a platform used by educational institutions. CVE-2026-47324 is a stored XSS flaw in student and teacher object attributes that normally requires an authorized user (teacher or admin) to inject malicious JavaScript, but becomes exploitable by a remote unauthenticated attacker when chained with CVE-2025-11661, a separate flaw allowing unauthenticated access to backend endpoints. CVE-2026-47325 compounds the risk by generating student and teacher passwords solely from date of birth with no forced password change on first login, making credentials trivially guessable.

The combination of these issues allows an unauthenticated remote attacker to both guess valid credentials and inject persistent JavaScript executed in other users' browsers, effectively enabling account compromise and session hijacking within school environments. The vendor was notified but did not provide information on which versions are affected; only the commit 6b6fae5 build was confirmed vulnerable, though other versions are likely impacted. No patch or fix has been confirmed as available at time of publication.

Mentioned in this report

Vulnerabilities CVE-2025-11661CVE-2026-47324CVE-2026-47325

Source reporting: https://cert.pl/en/posts/2026/06/CVE-2026-47324

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free