CVE-2024-25305: SQL Injection
Published Feb 9, 2024
·Updated
Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/index.php.
Affected Software
1 affected component
Code-projects Simple School Management System=1.0
Event History
Feb 9, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
May 4, 56090
Event
via FIRST·02:20 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-25305?
CVE-2024-25305 is considered to have a high severity due to its capability of allowing authentication bypass.
2
How do I fix CVE-2024-25305?
To fix CVE-2024-25305, ensure that proper authentication checks are implemented in the School/index.php file.
3
What software is affected by CVE-2024-25305?
CVE-2024-25305 affects version 1.0 of Code-projects Simple School Management System.
4
What type of vulnerability is CVE-2024-25305?
CVE-2024-25305 is classified as an Authentication Bypass vulnerability.
5
What are the potential impacts of CVE-2024-25305?
CVE-2024-25305 can allow unauthorized users to gain access to sensitive functionalities without proper authentication.