First published: Wed Dec 11 2024(Updated: )
A vulnerability, which was classified as critical, was found in code-projects Online Class and Exam Scheduling System 1.0. Affected is an unknown function of the file /pages/rank_update.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Online Class And Exam Scheduling System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-12486 is classified as a critical vulnerability.
To fix CVE-2024-12486, update the Online Class and Exam Scheduling System to a version that addresses the SQL injection vulnerability.
CVE-2024-12486 is an SQL injection vulnerability affecting the /pages/rank_update.php file.
Exploiting CVE-2024-12486 can allow attackers to manipulate database queries, potentially leading to unauthorized data access or modification.
CVE-2024-12486 affects the Online Class and Exam Scheduling System version 1.0.