CVE-2024-26517: SQL Injection
Published May 14, 2024
·Updated
SQL Injection vulnerability in School Task Manager v.1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the delete-task.php component.
Affected Software
2 affected components
School Task Manager School Task Manager
rems School Task Manager=1.0
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 14, 2024
CVE Published
via NVD·03:09 PM
Data Sourced
via NVD·03:09 PM
DescriptionSeverityWeaknessAffected Software
Nov 5, 2024
Data Sourced
via MITRE·06:29 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-26517?
CVE-2024-26517 is classified as a high-severity SQL Injection vulnerability.
2
How can I fix CVE-2024-26517?
To fix CVE-2024-26517, sanitize and validate all user inputs and use prepared statements in SQL queries.
3
What are the potential impacts of CVE-2024-26517?
Exploitation of CVE-2024-26517 can lead to unauthorized access to sensitive information stored in the database.
4
Which components of School Task Manager are affected by CVE-2024-26517?
CVE-2024-26517 specifically affects the delete-task.php component of School Task Manager.
5
Who is impacted by CVE-2024-26517?
Any user of School Task Manager v.1.0 is potentially impacted by CVE-2024-26517.