PT-2025-10057 · WordPress · School Management System

Khayal Farzaliyev

+1

·

Published

2025-03-07

·

Updated

2025-03-08

·

CVE-2024-12609

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions School Management System for Wordpress plugin versions up to, and including, 92.0.0
Description The issue arises from insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the mj smgt view student attendance() function, specifically on the 'view-attendance' page. This allows authenticated attackers with Student-level access and above to append additional SQL queries into already existing queries, potentially extracting sensitive information from the database.
Recommendations For School Management System for Wordpress plugin versions up to, and including, 92.0.0, consider restricting access to the 'view-attendance' page until a patch is available, and limit the use of the mj smgt view student attendance() function to prevent potential SQL injection attacks.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-12609

Affected Products

School Management System