First published: Thu Mar 07 2024(Updated: )
Chat functionality in Schoolbox application before version 23.1.3 is vulnerable to blind SQL Injection enabling the authenticated attackers to read, modify, and delete database records.
Credit: vdp@themissinglink.com.au
Affected Software | Affected Version | How to fix |
---|---|---|
Schoolbox | <23.1.3 | |
Schoolbox | <23.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28094 has a high severity rating due to its potential for unauthorized access to sensitive database records.
To mitigate CVE-2024-28094, upgrade to Schoolbox version 23.1.3 or later to eliminate the SQL Injection vulnerability.
All versions of the Schoolbox application prior to version 23.1.3 are affected by CVE-2024-28094.
CVE-2024-28094 is identified as a blind SQL Injection vulnerability in the chat functionality of the Schoolbox application.
Yes, CVE-2024-28094 can potentially allow authenticated attackers to read, modify, or delete database records, leading to data loss.