PT-2024-33324 · Unknown · Kashipara College Management System

Ssl_Seven_Security Lab_Wangzhiqiang_Xiaozilong

·

Published

2024-05-15

·

Updated

2024-07-08

·

CVE-2024-4905

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kashipara College Management System version 1.0
Description A critical issue has been discovered, allowing for remote attacks. The problem arises from the manipulation of the id argument, leading to SQL injection in the view students each detail.php file. The issue has been publicly disclosed and may be exploited.
Recommendations For Kashipara College Management System version 1.0, patch immediately and validate input on the view students each detail.php file to prevent SQL injection attacks. Additionally, consider auditing for other potential vulnerabilities to ensure system security. As a temporary workaround, consider restricting access to the view students each detail.php file until a patch is applied.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-4905

Affected Products

Kashipara College Management System