PT-2024-18425 · Sourcecodester · Simple Student Attendance System

Reiginald

·

Published

2024-02-27

·

Updated

2024-12-06

·

CVE-2024-1923

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Simple Student Attendance System version 1.0
Description A critical issue was found in the function delete class/delete student of the file /ajax-api.php of the component List of Classes Page. The manipulation of the argument id with the input 1337'+or+1=1;--+ leads to SQL injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Recommendations As a temporary workaround, consider disabling the delete class and delete student functions until a patch is available. Restrict access to the /ajax-api.php file to minimize the risk of exploitation. Avoid using the id argument in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-1923

Affected Products

Simple Student Attendance System