PT-2024-17619 · Unknown · Code-Projects Online Class/Exam Scheduling System

T123

·

Published

2024-12-11

·

Updated

2024-12-13

·

CVE-2024-12486

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions code-projects Online Class and Exam Scheduling System version 1.0
Description A critical issue has been found in the system, affecting an unknown function of the file /pages/rank update.php. The manipulation of the id argument leads to SQL injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Recommendations For code-projects Online Class and Exam Scheduling System version 1.0, consider disabling the affected function in the /pages/rank update.php file until a patch is available. Restrict access to the id argument to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-12486

Affected Products

Code-Projects Online Class/Exam Scheduling System