CVE-2024-13025: Codezips College Management System faculty.php sql injection
Published Dec 29, 2024
·Updated
A vulnerability was found in Codezips College Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /Front-end/faculty.php. The manipulation of the argument bookname/bookauthor leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Codezips College Management System
Codezips College Management System=1.0
Event History
Dec 29, 2024
CVE Published
via MITRE·10:31 PM
Data Sourced
via MITRE·10:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Oct 27, 57234
Event
via NVD·05:41 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-13025?
CVE-2024-13025 has been classified as a critical vulnerability.
2
What type of vulnerability is CVE-2024-13025?
CVE-2024-13025 is a SQL injection vulnerability.
3
Which component of Codezips College Management System is affected by CVE-2024-13025?
The affected component is an unknown function of the file /Front-end/faculty.php.
4
How can I mitigate CVE-2024-13025?
To mitigate CVE-2024-13025, sanitize and validate user inputs to prevent SQL injection.
5
What functions are manipulated to exploit CVE-2024-13025?
The vulnerability is exploited by manipulating the arguments book_name and book_author.