SQL Injection Vulnerability in Campcodes Complete Web-Based School Management System
CVE-2024-33804
6.3MEDIUM
Summary
A SQL injection vulnerability exists in the /model/get_subject.php file of Campcodes Complete Web-Based School Management System 1.0. This flaw allows attackers to manipulate SQL queries by injecting arbitrary commands through the 'id' parameter. By exploiting this vulnerability, an attacker may gain unauthorized access to the database, allowing potential exposure of sensitive information, modification of data, or even complete control over the database. Organizations using this version of the software should take immediate action to safeguard their applications from potential abuses.
References
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published