PT-2024-22872 · Unknown · Campcodes Online Examination System

Willchen

·

Published

2024-03-26

·

Updated

2025-02-20

·

CVE-2024-2938

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Campcodes Online Examination System version 1.0
Description A critical issue affects the processing of the file /adminpanel/admin/facebox modal/updateCourse.php. The manipulation of the id argument leads to sql injection. The attack may be initiated remotely.
Recommendations For Campcodes Online Examination System version 1.0, consider disabling the updateCourse.php file or restricting access to it until a patch is available. Avoid using the id argument in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-2938

Affected Products

Campcodes Online Examination System