CVE-2024-33808: SQL Injection
Published May 28, 2024
·Updated
A SQL injection vulnerability in /model/gettimetable.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.
Affected Software
2 affected components
Campcodes School Management Software
Campcodes School Management Software=1.0
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 28, 2024
CVE Published
via NVD·04:15 PM
Aug 20, 2024
Data Sourced
via MITRE·03:35 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-33808?
CVE-2024-33808 is classified as a critical SQL injection vulnerability.
2
How do I fix CVE-2024-33808?
To fix CVE-2024-33808, implement parameterized queries or use prepared statements to sanitize input.
3
Which software is affected by CVE-2024-33808?
CVE-2024-33808 affects Campcodes Complete Web-Based School Management System version 1.0.
4
What types of attacks can CVE-2024-33808 enable?
CVE-2024-33808 can enable attackers to execute arbitrary SQL commands, potentially compromising database security.
5
Has CVE-2024-33808 been exploited in the wild?
As of now, there are no public reports confirming in-the-wild exploitation of CVE-2024-33808.