leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-249502 is the identifier assigned to this vulnerability.", "datePublished": "2024-01-02T18:00:04Z", "dateModified": "2025-05-09T19:54:47Z", "keywords": "CVE-2024-0189, vulnerability, CVE, security, Nueva Ecija Engineer Online Portal, RRJ", "about": { "@type": "SoftwareApplication", "name": "Nueva Ecija Engineer Online Portal", "applicationCategory": "SecurityApplication", "operatingSystem": "All" } }
CVE-2024-0189 LOW

CVE-2024-0189: RRJ Nueva Ecija Engineer Online Portal Create Message teacher_message.php cross site scripting

Vendor Rrj
Product Nueva Ecija Engineer Online Portal
Weakness CWE-79 · XSS
Published January 2, 2024
Last update May 9, 2025

CVSS base score

3.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

A vulnerability has been found in RRJ Nueva Ecija Engineer Online Portal 1.0 and classified as problematic. This vulnerability affects unknown code of the file teacher_message.php of the component Create Message Handler. The manipulation of the argument Content with the input </title><scRipt>alert(x)</scRipt> leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-249502 is the identifier assigned to this vulnerability.

Key dates

02Disclosure timeline

January 2, 2024 CVE published
May 9, 2025 Record updated

Related vulnerabilities

04Related CVE