SQL Injection Vulnerability in Campcodes Web-Based School Management System
CVE-2024-33402
8.1HIGH
Summary
A vulnerability exists in the Campcodes Complete Web-Based School Management System 1.0 that enables an attacker to exploit the system through an SQL injection. This occurs via the 'id' parameter in the /model/approve_petty_cash.php script, allowing unauthorized users to execute arbitrary SQL commands. This capability can lead to unauthorized data access, data manipulation, and potentially compromise the integrity and confidentiality of the data stored within the system. It is critical for administrators to implement appropriate security measures to protect against such SQL injection attacks.
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published