PT-2024-36440 · Unknown · Kashipara E-Learning Management System

Published

2024-12-09

·

Updated

2024-12-12

·

CVE-2024-54922

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions kashipara E-learning Management System version 1.0
Description A SQL Injection issue was found in the /admin/edit user.php file, allowing remote attackers to execute arbitrary SQL commands and gain unauthorized access to the database via the firstname, lastname, and username parameters. This issue enables attackers to access sensitive data without proper authorization.
Recommendations For kashipara E-learning Management System version 1.0, consider disabling access to the /admin/edit user.php file until a patch is available. Restrict input for the firstname, lastname, and username parameters to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-54922

Affected Products

Kashipara E-Learning Management System