CVE-2019-14696: Open-School

Medium severity, CVSS 6.1. EPSS: 15.7% chance of exploitation in the next 30 days.

Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter.

Affected products

  • Open-School Open-School: version 2.3 only; version 3.0 only

Published 2019-08-06. Last modified 2026-06-17.