PT-2024-32477 · Campcodes · Campcodes Complete Web-Based School Management System

Ssl_Seven_Security Lab_Wangzhiqiang_Xiaozilong

·

Published

2024-05-10

·

Updated

2024-06-04

·

CVE-2024-4720

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Campcodes Complete Web-Based School Management System version 1.0
Description A issue was found in the file /model/approve petty cash.php, where the manipulation of the admin index argument leads to cross site scripting. This can be exploited remotely.
Recommendations For Campcodes Complete Web-Based School Management System version 1.0, as a temporary workaround, consider restricting access to the /model/approve petty cash.php file until a patch is available. Avoid using the admin index argument in the affected file to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-4720

Affected Products

Campcodes Complete Web-Based School Management System