SQL Injection Vulnerability in Campcodes Web-Based School Management System
CVE-2024-33402
8.1HIGH
What is CVE-2024-33402?
A vulnerability exists in the Campcodes Complete Web-Based School Management System 1.0 that enables an attacker to exploit the system through an SQL injection. This occurs via the 'id' parameter in the /model/approve_petty_cash.php script, allowing unauthorized users to execute arbitrary SQL commands. This capability can lead to unauthorized data access, data manipulation, and potentially compromise the integrity and confidentiality of the data stored within the system. It is critical for administrators to implement appropriate security measures to protect against such SQL injection attacks.