SQL Injection Vulnerability in Web-Based School Management System
CVE-2024-34933
6.3MEDIUM
What is CVE-2024-34933?
A vulnerability exists in the Campcodes Complete Web-Based School Management System 1.0 due to improper handling of input in the /model/update_grade.php file. An attacker can exploit this SQL injection flaw by manipulating the admission_fee parameter to execute arbitrary SQL commands. This exploitation could lead to unauthorized access to sensitive data, alterations in the database content, and further compromise the integrity of the system. Organizations using this system should prioritize immediate remediation to safeguard against potential attacks and protect user data.