Authentication Bypass Vulnerability in Simple School Managment System 1.0
CVE-2024-25313
8.8HIGH
Summary
The Simple School Management System, version 1.0 developed by Code-projects, contains a significant vulnerability that permits authentication bypass through manipulation of the username and password fields at the login interface (School/teacher_login.php). This flaw exposes the system to unauthorized user access, potentially compromising sensitive information and user accounts. Effective security measures and timely updates are recommended to mitigate the risks associated with this vulnerability.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved