First published: Tue Feb 27 2024(Updated: )
A vulnerability was found in SourceCodester Simple Student Attendance System 1.0 and classified as critical. Affected by this issue is the function delete_class/delete_student of the file /ajax-api.php of the component List of Classes Page. The manipulation of the argument id with the input 1337'+or+1=1;--+ leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-254858 is the identifier assigned to this vulnerability.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sourcecodester Simple Student Attendance System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1923 is classified as a critical vulnerability.
CVE-2024-1923 affects the delete_class/delete_student functions in the /ajax-api.php file of the SourceCodester Simple Student Attendance System version 1.0.
To fix CVE-2024-1923, it is recommended to update the SourceCodester Simple Student Attendance System to a patched version.
CVE-2024-1923 is primarily identified as an SQL injection vulnerability.
CVE-2024-1923 can potentially allow remote attackers to manipulate database queries through crafted input.