PT-2024-20872 · Sourcecodester · Sourcecodester Student Attendance Management System

Tuba Kavgacı

·

Published

2024-02-09

·

Updated

2024-03-03

·

CVE-2024-25302

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sourcecodester Event Student Attendance System version 1.0
Description The issue allows SQL Injection via the student parameter. This could potentially lead to unauthorized access or manipulation of database content. There is no information provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.
Recommendations For Sourcecodester Event Student Attendance System version 1.0, as a temporary workaround, consider restricting access to the student parameter in the affected API endpoint until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-25302

Affected Products

Sourcecodester Student Attendance Management System