PT-2024-30033 · Unknown · School Management System

Topsky979

·

Published

2024-08-20

·

Updated

2024-08-21

·

CVE-2024-42572

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions School Management System (affected versions not specified)
Description A SQL injection issue was discovered in the School Management System via the medium parameter at the "unitmarks.php" endpoint. This allows for potential exploitation. No information is available on the estimated number of affected devices or real-world incidents.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-42572

Affected Products

School Management System