CVE-2024-0497

A vulnerability was found in Campcodes Student Information System 1.0. It has been classified as critical. Affected is an unknown function of the file /classes/Users.php?f=save. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-250602 is the identifier assigned to this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:campcodes:simple_student_information_system:1.0:*:*:*:*:*:*:*

History

19 Jan 2024, 18:55

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad en Campcodes Student Information System 1.0. Ha sido clasificada como crítica. Una función desconocida del archivo /classes/Users.php?f=save es afectada por esta vulnerabilidad. La manipulación del argumento username conduce a la inyección de SQL. Es posible lanzar el ataque de forma remota. La explotación ha sido divulgada al público y puede utilizarse. VDB-250602 es el identificador asignado a esta vulnerabilidad.
First Time Campcodes simple Student Information System
Campcodes
References () https://github.com/laoquanshi/heishou/blob/main/SQL%20injection%20exists%20in%20student%20information%20system%20.docx - () https://github.com/laoquanshi/heishou/blob/main/SQL%20injection%20exists%20in%20student%20information%20system%20.docx - Broken Link
References () https://vuldb.com/?ctiid.250602 - () https://vuldb.com/?ctiid.250602 - Third Party Advisory
References () https://vuldb.com/?id.250602 - () https://vuldb.com/?id.250602 - Third Party Advisory
CPE cpe:2.3:a:campcodes:simple_student_information_system:1.0:*:*:*:*:*:*:*
CVSS v2 : 6.5
v3 : 6.3
v2 : 6.5
v3 : 9.8

13 Jan 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-13 18:15

Updated : 2024-05-17 02:34


NVD link : CVE-2024-0497

Mitre link : CVE-2024-0497

CVE.ORG link : CVE-2024-0497


JSON object : View

Products Affected

campcodes

  • simple_student_information_system
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')