PT-2023-31441 · Unknown · School Management System

Geraldo Alcântara

·

Published

2023-12-20

·

Updated

2024-10-28

·

CVE-2023-49982

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions School Fees Management System version 1.0
Description The issue allows attackers to escalate privileges and perform administrative actions, including adding and deleting user accounts, due to broken access control in the /admin/management/users component.
Recommendations For School Fees Management System version 1.0, consider restricting access to the /admin/management/users component until a fix is available. As a temporary workaround, limit the ability to add and delete user accounts to prevent privilege escalation.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-49982

Affected Products

School Management System