PT-2024-29325 · Unknown · Kashipara Responsive School Management System

Published

2024-08-07

·

Updated

2024-08-08

·

CVE-2024-41247

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Kashipara Responsive School Management System version 3.2.0
Description An issue was found in the Kashipara Responsive School Management System, where incorrect access control allows remote unauthenticated attackers to add new class entries. The issue is specifically related to the /smsa/add class.php and /smsa/add class submit.php endpoints.
Recommendations For Kashipara Responsive School Management System version 3.2.0, consider restricting access to the /smsa/add class.php and /smsa/add class submit.php endpoints until a patch is available. As a temporary workaround, limit the ability to add new class entries to authenticated and authorized users only.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-41247

Affected Products

Kashipara Responsive School Management System