CVE-2024-4824

CVSS V2 None CVSS V3 None
Description
Vulnerability in School ERP Pro+Responsive 1.0 that allows SQL injection through the '/SchoolERP/office_admin/' index in the parameters groups_id, examname, classes_id, es_voucherid, es_class, etc. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the database.
Overview
  • CVE ID
  • CVE-2024-4824
  • Assigner
  • INCIBE
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-05-13T11:29:37.151Z
  • Last Modified Date
  • 2024-06-04T17:53:38.941Z
History
Created Old Value New Value Data Type Notes
2024-06-23 22:16:53 Added to TrackCVE