Authentication Bypass Vulnerability in Simple School Managment System 1.0
CVE-2024-25313

8.8HIGH

Key Information:

Vendor
CVE Published:
9 February 2024

Summary

The Simple School Management System, version 1.0 developed by Code-projects, contains a significant vulnerability that permits authentication bypass through manipulation of the username and password fields at the login interface (School/teacher_login.php). This flaw exposes the system to unauthorized user access, potentially compromising sensitive information and user accounts. Effective security measures and timely updates are recommended to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-25313 : Authentication Bypass Vulnerability in Simple School Managment System 1.0 | SecurityVulnerability.io