An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the HTTP Response Header Settings component.
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.