PT-2024-36449 · Unknown · Kashipara E-Learning Management System

Published

2024-12-09

·

Updated

2024-12-11

·

CVE-2024-54931

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions kashipara E-learning Management System version 1.0
Description A SQL Injection issue was found in the /admin/delete event.php endpoint, allowing remote attackers to execute arbitrary SQL commands and gain unauthorized database access via the id parameter. This issue enables attackers to manipulate database queries, potentially leading to data breaches or other malicious activities.
Recommendations For kashipara E-learning Management System version 1.0, consider disabling access to the /admin/delete event.php endpoint until a patch is available, or restrict the use of the id parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-54931

Affected Products

Kashipara E-Learning Management System