CVE-2014-1914: Doug Poulin Command School Student Management System

Medium severity, CVSS 4.3. EPSS: 1.3% chance of exploitation in the next 30 days.

Multiple cross-site scripting (XSS) vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to inject arbitrary web script or HTML via the (1) topic parameter to sw/add_topic.php or (2) nick parameter to sw/chat/message.php.

Affected products

  • Doug Poulin Command School Student Management System: version 1.06.01 only

Published 2014-02-07. Last modified 2026-06-17.