SQL Injection Vulnerability in Campcodes Complete Web-Based School Management System
CVE-2024-33804
6.3MEDIUM
What is CVE-2024-33804?
A SQL injection vulnerability exists in the /model/get_subject.php file of Campcodes Complete Web-Based School Management System 1.0. This flaw allows attackers to manipulate SQL queries by injecting arbitrary commands through the 'id' parameter. By exploiting this vulnerability, an attacker may gain unauthorized access to the database, allowing potential exposure of sensitive information, modification of data, or even complete control over the database. Organizations using this version of the software should take immediate action to safeguard their applications from potential abuses.