PT-2024-29328 · Unknown · Kashipara Responsive School Management System

Published

2024-08-07

·

Updated

2024-10-24

·

CVE-2024-41250

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kashipara Responsive School Management System version 3.2.0
Description An issue was found in the /smsa/view students.php endpoint, allowing remote unauthenticated attackers to view student details. This issue affects the ability to control access correctly.
Recommendations For Kashipara Responsive School Management System version 3.2.0, consider restricting access to the /smsa/view students.php endpoint until a patch is available. As a temporary workaround, limit the information that can be viewed through this endpoint to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-41250

Affected Products

Kashipara Responsive School Management System