PT-2024-29329 · Unknown · Kashipara Responsive School Management System

Published

2024-08-07

·

Updated

2024-10-24

·

CVE-2024-41251

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kashipara Responsive School Management System version 3.2.0
Description An issue was found in the /smsa/admin teacher register approval.php and /smsa/admin teacher register approval submit.php API endpoints, allowing remote unauthenticated attackers to view and approve teacher registrations.
Recommendations For Kashipara Responsive School Management System version 3.2.0, consider restricting access to the /smsa/admin teacher register approval.php and /smsa/admin teacher register approval submit.php API endpoints to prevent unauthorized viewing and approval of teacher registrations. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-41251

Affected Products

Kashipara Responsive School Management System