Cross-site scripting (XSS) vulnerability in schoolmv2/html/studentmain.php in SchoolMation 2.3 allows remote attackers to inject arbitrary web script or HTML via the session parameter.Referenceshttp://osvdb.org/65417http://packetstormsecurity.org/1006-exploits/schoolmation-sqlxss.txthttp://www.exploit-db.com/exploits/13812/http://secunia.com/advisories/40154http://www.securityfocus.com/bid/40737https://exchange.xforce.ibmcloud.com/vulnerabilities/59346http://securityreason.com/securityalert/8508