SQL Injection Vulnerability in School Activity Updates SMS Notification by Wsatm
CVE-2022-38878
7.2HIGH
Key Information:
- Vendor
- CVE Published:
- 16 September 2022
What is CVE-2022-38878?
The School Activity Updates with SMS Notification version 1.0 is exposed to an SQL injection vulnerability that allows attackers to manipulate database queries through the 'id' parameter in the /activity/admin/modules/event/index.php?view=edit URL. This could potentially lead to unauthorized data access or integrity compromise, making it critical for users to implement security measures against this exploit.
