SQL Injection Vulnerability in Campcodes Complete Web-Based School Management System
CVE-2024-33804

6.3MEDIUM

Key Information:

Vendor
Campcodes
Vendor
CVE Published:
28 May 2024

Summary

A SQL injection vulnerability exists in the /model/get_subject.php file of Campcodes Complete Web-Based School Management System 1.0. This flaw allows attackers to manipulate SQL queries by injecting arbitrary commands through the 'id' parameter. By exploiting this vulnerability, an attacker may gain unauthorized access to the database, allowing potential exposure of sensitive information, modification of data, or even complete control over the database. Organizations using this version of the software should take immediate action to safeguard their applications from potential abuses.

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2024-33804 : SQL Injection Vulnerability in Campcodes Complete Web-Based School Management System | SecurityVulnerability.io