PT-2025-26833 · Unknown · Student Record System Using Php/Mysql

Published

2025-06-25

·

Updated

2025-06-30

·

CVE-2024-27685

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Student Record system Using PHP and MySQL version 3.20
Description: The issue allows a remote attacker to obtain sensitive information via a crafted payload to the cshortname, cfullname, and cdate variables. This is a SQL Injection vulnerability.
Recommendations: For version 3.20, consider restricting access to the vulnerable variables cshortname, cfullname, and cdate to minimize the risk of exploitation. Avoid using these variables in API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-27685

Affected Products

Student Record System Using Php/Mysql