PT-2024-37506 · Unknown · Lahirudanushka School Management System

Louay Khammassi

·

Published

2024-06-24

·

Updated

2024-09-09

·

CVE-2024-6278

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: lahirudanushka School Management System versions 1.0.0 through 1.0.1
Description: A critical issue has been found in the lahirudanushka School Management System, affecting an unknown functionality of the file subject.php of the component Subject Page. The manipulation of the update argument leads to SQL injection. The attack can be launched remotely.
Recommendations: For lahirudanushka School Management System versions 1.0.0 through 1.0.1, consider restricting access to the subject.php file of the Subject Page component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-6278

Affected Products

Lahirudanushka School Management System