PT-2024-30028 · Unknown · School Management System

Topsky979

·

Published

2024-08-20

·

Updated

2024-09-03

·

CVE-2024-42568

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions School Management System (affected versions not specified)
Description A SQL injection issue was discovered in the School Management System, specifically via the transport parameter at the "vehicle.php" endpoint. This allows for potential exploitation. No information is provided about the estimated number of affected devices or real-world incidents.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-42568

Affected Products

School Management System