{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/teachers-record-management-system-1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:teacher_record_management_system_project:teacher_record_management_system:1.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":4.8,"id":"CVE-2022-41445"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Teachers Record Management System (1.0)"],"_cs_severities":["low"],"_cs_tags":["xss","web-vulnerability","stored-xss"],"_cs_type":"advisory","_cs_vendors":["Phpgurukul"],"content_html":"\u003cp\u003ePhpgurukul Teachers Record Management System version 1.0 contains a stored cross-site scripting (XSS) vulnerability identified as CVE-2022-41445. The vulnerability resides in the 'Add Subject' page of the application, which leverages the CodeIgniter framework. An authenticated attacker with administrative privileges can inject malicious JavaScript payloads into subject entry fields. When a teacher user subsequently accesses the profile details page, the stored script executes in the victim's browser session. This vulnerability poses a risk of session hijacking, unauthorized actions performed on behalf of the teacher, or information theft within the administrative and teacher interfaces. The availability of proof-of-concept exploit material increases the risk of exploitation for organizations still running this version.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the Teachers Record Management System using valid administrative credentials.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the 'Add Subject' administration page.\u003c/li\u003e\n\u003cli\u003eAttacker inputs a crafted JavaScript payload into the subject title or related input fields.\u003c/li\u003e\n\u003cli\u003eAttacker submits the form, causing the malicious script to be saved into the application's backend database.\u003c/li\u003e\n\u003cli\u003eA teacher user logs into the application and navigates to their profile view or a page listing subject details.\u003c/li\u003e\n\u003cli\u003eThe application retrieves the stored malicious payload from the database and renders it unsanitized in the teacher's browser.\u003c/li\u003e\n\u003cli\u003eThe browser executes the malicious JavaScript, potentially exfiltrating session cookies or performing unauthorized actions.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the execution of unauthorized JavaScript in the context of a teacher's browser session. This can lead to the compromise of teacher accounts, unauthorized data access, and potential escalation of impact within the system's administrative environment. The severity is CVSS 4.8, reflecting the requirement for administrative privileges and user interaction.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnsure all users of the Phpgurukul Teachers Record Management System upgrade to the latest version if available, or apply vendor-provided patches.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation and output encoding for all user-controllable fields, specifically targeting the 'Add Subject' and profile view modules in the application source code.\u003c/li\u003e\n\u003cli\u003eMonitor administrative account activity for suspicious subject creation or modifications.\u003c/li\u003e\n\u003cli\u003eRestrict access to administrative modules to verified, high-trust users only.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-29T12:44:50Z","date_published":"2026-08-29T12:44:50Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2022-41445/","summary":"A stored cross-site scripting (XSS) vulnerability in Phpgurukul Teachers Record Management System version 1.0 allows authenticated administrators to execute arbitrary JavaScript in the context of other users.","title":"Stored XSS Vulnerability in Phpgurukul Teachers Record Management System","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2022-41445/"}],"language":"en","title":"CraftedSignal Threat Feed - Teachers Record Management System (1.0)","version":"https://jsonfeed.org/version/1.1"}