SQL Injection Vulnerability in Web-Based School Management System
CVE-2024-34933

6.3MEDIUM

Key Information:

Vendor
Campcodes
Vendor
CVE Published:
23 May 2024

Summary

A vulnerability exists in the Campcodes Complete Web-Based School Management System 1.0 due to improper handling of input in the /model/update_grade.php file. An attacker can exploit this SQL injection flaw by manipulating the admission_fee parameter to execute arbitrary SQL commands. This exploitation could lead to unauthorized access to sensitive data, alterations in the database content, and further compromise the integrity of the system. Organizations using this system should prioritize immediate remediation to safeguard against potential attacks and protect user data.

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2024-34933 : SQL Injection Vulnerability in Web-Based School Management System | SecurityVulnerability.io