CVE-2014-1914: Doug Poulin Command School Student Management System
Medium severity, CVSS 4.3. EPSS: 1.3% chance of exploitation in the next 30 days.
Multiple cross-site scripting (XSS) vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to inject arbitrary web script or HTML via the (1) topic parameter to sw/add_topic.php or (2) nick parameter to sw/chat/message.php.
Affected products
- Doug Poulin Command School Student Management System: version 1.06.01 only
Published 2014-02-07. Last modified 2026-06-17.