Release date:
Updated on:
Affected Systems:
Pearsonschoolsystems eSIS
Description:
--------------------------------------------------------------------------------
Bugtraq id: 66673
CVE (CAN) ID: CVE-2014-1454
Pearson eSIS is an enterprise-level student information system.
Pearson eSIS has the HTML injection vulnerability in implementation. After successful exploitation, attackers can inject and execute HTML and script code in the context of the affected browser.
<* Source: Tudor Enache
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Pearsonschoolsystems
--------------------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Www.pearsonschoolsystems.com/products/esis