CVE-2024-25306: SQL Injection
Published Feb 9, 2024
·Updated
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'aname' parameter at "School/index.php".
Affected Software
1 affected component
Code-projects Simple School Management System=1.0
Event History
Feb 9, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
May 4, 56090
Event
via FIRST·02:17 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-25306?
CVE-2024-25306 has been assessed to have a high severity due to the potential for SQL injection attacks.
2
How do I fix CVE-2024-25306?
To fix CVE-2024-25306, validate and sanitize the 'aname' parameter to prevent unauthorized SQL commands.
3
What software is affected by CVE-2024-25306?
CVE-2024-25306 affects the Simple School Management System version 1.0.
4
Can CVE-2024-25306 lead to data breaches?
Yes, CVE-2024-25306 can potentially lead to data breaches by allowing attackers to manipulate database queries.
5
Is CVE-2024-25306 remote exploitable?
Yes, CVE-2024-25306 can be exploited remotely due to its exposure through a web application.