yungifez Skuul School Management System, Cross-Site Scripting, CVE-2025-13784 (MEDIUM)

Listen to this Post

This vulnerability exists within the SVG File Handler component of the yungifez Skuul School Management System (up to version 2.6.5). The affected endpoint is /dashboard/schools/1/edit. The system fails to properly sanitize user-controllable input that is processed as an SVG file. Since Scalable Vector Graphics (SVG) files can contain JavaScript within `

Scroll to Top