CVE-2024-25304: SQL Injection
Published Feb 9, 2024
·Updated
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'apass' parameter at "School/index.php."
Affected Software
1 affected component
Code-projects Simple School Management System=1.0
Event History
Feb 9, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
May 4, 56090
Event
via FIRST·02:20 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-25304?
CVE-2024-25304 is classified as a high severity vulnerability due to the potential for SQL injection leading to unauthorized database access.
2
How do I fix CVE-2024-25304?
To fix CVE-2024-25304, sanitize and validate the 'apass' parameter input to prevent SQL injection attacks.
3
What type of vulnerability is CVE-2024-25304?
CVE-2024-25304 is an SQL Injection vulnerability that affects the Simple School Management System.
4
Which software is affected by CVE-2024-25304?
CVE-2024-25304 affects the Simple School Management System version 1.0.
5
Where is the SQL injection vulnerability located in CVE-2024-25304?
The SQL injection vulnerability in CVE-2024-25304 is located in the 'apass' parameter at the path "School/index.php."